What to do when a company refuses to fix a vulnerability I disclosed to them?
51–60 of 74 posts
Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#52There are security companies that buy these kind of information from you (like antivirus companies), so that they can patch the breaches themselves and proudly announce they discovered a breach and only by using their software you can be protected. I don't know how legal it is, and I understand that the breach finder wants to publish his findings himself (for "reputations points" maybe ?), and he might lose this righ…
Nobody is going to buy a rate limiting bug in some random mobile application. Actually: nobody is going to buy a rate limiting bug at all.
Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#53Earlier quoted context omitted.
Or rather you contact them. Then they ban you and possibly send the FBI after you for "illegally accessing a remote computer system" or other such crime and then you are punished for all your work. If you tell them you will disclose your research on a certain date they'll go after you for extortion. I wrote this before and I'll say it again. I don't believe in "White Hacker" as a label. Corporations do not do well wh…
I don't believe it is extortion since all he is asking them to do is fix their own vulnerability. I believe extortion requires the demand of money or services in exchange for action/inaction.
Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#54Public disclosure won't help btw. half of sites here didn't fix anything( http://homakov.blogspot.com/2012/03/hacking-skrillformer-mon... )
Did you reach out to each company and tell them, or did you assume that by creating a public blog post about them and submitting it to Hacker News they were bound to find out?
Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#55Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#56I think you're supposed to exploit the vulnerability in relatively innocuous but deeply disturbing ways, get banned, then complain about how you only meant well, then be lauded on Hacker News as a martyr who should have been embraced by the hacked company.
Or rather you contact them. Then they ban you and possibly send the FBI after you for "illegally accessing a remote computer system" or other such crime and then you are punished for all your work. If you tell them you will disclose your research on a certain date they'll go after you for extortion. I wrote this before and I'll say it again. I don't believe in "White Hacker" as a label. Corporations do not do well wh…
Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#57Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#58Earlier quoted context omitted.
Did you reach out to each company and tell them, or did you assume that by creating a public blog post about them and submitting it to Hacker News they were bound to find out?
Did you read his blog post and see that he did report the vulnerabilities and noted which companies fixed it?
I've been doing this for awhile, maybe there's useful advice I can offer him.
Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#59Earlier quoted context omitted.
I don't believe it is extortion since all he is asking them to do is fix their own vulnerability. I believe extortion requires the demand of money or services in exchange for action/inaction.
Isn't fixing the vulnerability a demand of services?
Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#60Earlier quoted context omitted.
I don't believe it is extortion since all he is asking them to do is fix their own vulnerability. I believe extortion requires the demand of money or services in exchange for action/inaction.
Isn't fixing the vulnerability a demand of services?