Earlier quoted context omitted.
Or rather you contact them. Then they ban you and possibly send the FBI after you for "illegally accessing a remote computer system" or other such crime and then you are punished for all your work. If you tell them you will disclose your research on a certain date they'll go after you for extortion. I wrote this before and I'll say it again. I don't believe in "White Hacker" as a label. Corporations do not do well wh…
If you tell them that unless they pay you or retain you as a contractor by a certain date that you'll publish, you are in fact extorting them. People who have found vulnerabilities and also been naive about the law have run aground on this before.
What to do when a company refuses to fix a vulnerability I disclosed to them?
61–70 of 74 posts
Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#62Seems pretty straightforward to me -- since it's a DoS that doesn't put users' information at risk, just publish it without naming the company.
Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#63Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#64Earlier quoted context omitted.
If you tell them that unless they pay you or retain you as a contractor by a certain date that you'll publish, you are in fact extorting them. People who have found vulnerabilities and also been naive about the law have run aground on this before.
Do you have any examples?
Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#65If only the company is put in danger and they stubbornly refuse to resolve the issue, I'm not exactly sure why anyone would work so hard to convince a company to do this. The job of reporting the issue is done, a corporate decision has been made. If that decision is to remain vulnerable, as long as it does not affect users directly, why bother? Unless, as others suggested, you can legally make a profit out of it, the…
It appears he wants to publish the vulnerability (might be a novice security researcher) without getting sued.
Contrary to popular opinion on HN, finding vulnerabilities in software you yourself run on your own computer is rarely fraught. We hear about the exceptions in the news because they're exceptional. In reality, people publish vulnerabilities all the time.
The same thing obviously CANNOT BE SAID about finding vulnerabilities in other people's web applications. Finding web vulnerabilities without permission is highly fraught. You can easily find yourself both civilly and criminally liable for doing so.
Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#66I'm curious what we could change legally to make this less an issue. There's a clear conflict of interest between doing a public good by disclosing a vulnerability and not wanting to risk (at worst) the FBI coming after you or (at best) losing clients. I would certainly consider it unethical to know of a vulnerability and not disclose that information publicly, but there are so many hurdles to doing so that I don't b…
Most of the stories you hear about people getting in actual trouble over vulnerability research involve web vulnerabilities. You cannot hack someone else's web site to make a point, even if the underlying point is unimpeachable ("this application is insecure and people should know about it").
Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#67Earlier quoted context omitted.
Or rather you contact them. Then they ban you and possibly send the FBI after you for "illegally accessing a remote computer system" or other such crime and then you are punished for all your work. If you tell them you will disclose your research on a certain date they'll go after you for extortion. I wrote this before and I'll say it again. I don't believe in "White Hacker" as a label. Corporations do not do well wh…
I believe you mean "White Hat Hacker"... I think everyone gets the gist of what you mean but just wanted to clarify in case someone's thinking you're a racist hating on "Whitie" or something :)
Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#68Earlier quoted context omitted.
I believe you mean "White Hat Hacker"... I think everyone gets the gist of what you mean but just wanted to clarify in case someone's thinking you're a racist hating on "Whitie" or something :)
Are there really people in this community who don't know this?
About 526,000 results
http://www.google.com/#hl=en&q=%22white+hat%22+hacker
About 65,000 results
http://www.google.com/search?hl=en&q=%22white%20hacker%22Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#69Re: What to do when a company refuses to fix a vulnerability I disclosed to them?
#70Earlier quoted context omitted.
Or rather you contact them. Then they ban you and possibly send the FBI after you for "illegally accessing a remote computer system" or other such crime and then you are punished for all your work. If you tell them you will disclose your research on a certain date they'll go after you for extortion. I wrote this before and I'll say it again. I don't believe in "White Hacker" as a label. Corporations do not do well wh…
I believe you mean "White Hat Hacker"... I think everyone gets the gist of what you mean but just wanted to clarify in case someone's thinking you're a racist hating on "Whitie" or something :)