Live data from Hacker News

What to do when a company refuses to fix a vulnerability I disclosed to them?

reddit.com

51–60 of 74 posts

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#52
post #35
post #2

There are security companies that buy these kind of information from you (like antivirus companies), so that they can patch the breaches themselves and proudly announce they discovered a breach and only by using their software you can be protected. I don't know how legal it is, and I understand that the breach finder wants to publish his findings himself (for "reputations points" maybe ?), and he might lose this righ…

Nobody is going to buy a rate limiting bug in some random mobile application. Actually: nobody is going to buy a rate limiting bug at all.

when I posted my comment the reddit post wasn't edited to say that it's a rate liming bug. Indeed, nobody is going to buy such a thing. Pretty useless for any kind of purposes, black-hat or not.

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#53
post #32
post #22

Earlier quoted context omitted.

Or rather you contact them. Then they ban you and possibly send the FBI after you for "illegally accessing a remote computer system" or other such crime and then you are punished for all your work. If you tell them you will disclose your research on a certain date they'll go after you for extortion. I wrote this before and I'll say it again. I don't believe in "White Hacker" as a label. Corporations do not do well wh…

I don't believe it is extortion since all he is asking them to do is fix their own vulnerability. I believe extortion requires the demand of money or services in exchange for action/inaction.

Isn't fixing the vulnerability a demand of services?

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#54
post #36
post #10

Public disclosure won't help btw. half of sites here didn't fix anything( http://homakov.blogspot.com/2012/03/hacking-skrillformer-mon... )

Did you reach out to each company and tell them, or did you assume that by creating a public blog post about them and submitting it to Hacker News they were bound to find out?

Did you read his blog post and see that he did report the vulnerabilities and noted which companies fixed it?

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#56
post #22
post #5

I think you're supposed to exploit the vulnerability in relatively innocuous but deeply disturbing ways, get banned, then complain about how you only meant well, then be lauded on Hacker News as a martyr who should have been embraced by the hacked company.

Or rather you contact them. Then they ban you and possibly send the FBI after you for "illegally accessing a remote computer system" or other such crime and then you are punished for all your work. If you tell them you will disclose your research on a certain date they'll go after you for extortion. I wrote this before and I'll say it again. I don't believe in "White Hacker" as a label. Corporations do not do well wh…

I believe you mean "White Hat Hacker"... I think everyone gets the gist of what you mean but just wanted to clarify in case someone's thinking you're a racist hating on "Whitie" or something :)

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#58
post #36

Earlier quoted context omitted.

Did you reach out to each company and tell them, or did you assume that by creating a public blog post about them and submitting it to Hacker News they were bound to find out?

Did you read his blog post and see that he did report the vulnerabilities and noted which companies fixed it?

I read the comment he wrote on HN where he said he didn't. But if Egor Homakov says he did, my next question is "who did he report it to?"

I've been doing this for awhile, maybe there's useful advice I can offer him.

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#59
post #32

Earlier quoted context omitted.

I don't believe it is extortion since all he is asking them to do is fix their own vulnerability. I believe extortion requires the demand of money or services in exchange for action/inaction.

Isn't fixing the vulnerability a demand of services?

[deleted]

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#60
post #32

Earlier quoted context omitted.

I don't believe it is extortion since all he is asking them to do is fix their own vulnerability. I believe extortion requires the demand of money or services in exchange for action/inaction.

Isn't fixing the vulnerability a demand of services?

Doubtful, or a lot of consumer demands are technically extortion. In particular, the model jury rules for extortion tend to refer specifically to property (usually money).
Post reply on HN