Earlier quoted context omitted.
Its never been legit for such burglars to gain access to a building and leave a note describing the poor security on the CEO's desk. Unless, of course, you happen to be Richard Feynman. Which most of us aren't. http://www.silvertrading.net/articles_lagniappe_01_richard_f...
I've had "Surely You're Joking" on my Kindle for almost a year now and have never read it, but every time I see anything written about Feynman I realize that I'm almost certainly missing out. He sounds like the most interesting man.
What to do when a company refuses to fix a vulnerability I disclosed to them?
41–50 of 74 posts
Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#42Earlier quoted context omitted.
I prefer the homakovs of the world rather than the Anons (they would take full advantage) of the world. To have one vulnerability that could lead to another is undesirable. Homakov's actions could be considered aggressive, but sometimes that's exactly what is needed in order to push something. (no pun intended)
The world does not divide into those two kinds of people.
Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#43Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#44It almost makes me feel that there should be a law requiring disclosure of vulnerabilities.
Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#45Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#46I recommend two shots of wheatgrass and a smoothie.
Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#47Earlier quoted context omitted.
If you do publish it, odds are they'll issue a DMCA takedown and try to sue. My experience is quite to the contrary. Even Intel, as poor as their security response was, didn't try to take legal action against me. (I was lucky that I was unemployed at the time, though...)
> didn't try to take legal action against me But that is an interesting attitude. Instead of being indignant that they didn't offer to pay you for doing their security research for them ( or at least publicly thanking you) you just seem glad that they didn't sue you. It is like volunteering to help someone and then just being glad they didn't beat you up in the end. So it seems like there is not much benefit to doing…
I didn't publish the hyperthreading vulnerability to help Intel. I published it to help Intel's customers.
Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#48If only the company is put in danger and they stubbornly refuse to resolve the issue, I'm not exactly sure why anyone would work so hard to convince a company to do this. The job of reporting the issue is done, a corporate decision has been made. If that decision is to remain vulnerable, as long as it does not affect users directly, why bother? Unless, as others suggested, you can legally make a profit out of it, the…
Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#49Earlier quoted context omitted.
I prefer the homakovs of the world rather than the Anons (they would take full advantage) of the world. To have one vulnerability that could lead to another is undesirable. Homakov's actions could be considered aggressive, but sometimes that's exactly what is needed in order to push something. (no pun intended)
The world does not divide into those two kinds of people.
Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#50Earlier quoted context omitted.
The world does not divide into those two kinds of people.
We can still agree homakov doesn't deserve this kind of lingering resentment on behalf of the OP.
But ideally this isn't going to be a subject you & I are going to end up having to argue about today.