LOL http://www.websmartconsulting.com/profile.php?ClientID='
Websmart, Inc. and 100,000 Vulnerable Websites
21–30 of 74 posts
Re: Websmart, Inc. and 100,000 Vulnerable Websites
#22Earlier quoted context omitted.
It doesn't seem that he felt like taking any action since 2010
Are you sure he was notified in those previous incidents? Sure, that's really poor behavior of the company, but you don't know if he was even aware. Sam should have responsibly disclosed the information assuming that it was not already known - his actions were indeed unprofessional and could've been approached differently - if there was still no action taken, then that's a whole other story.
Re: Websmart, Inc. and 100,000 Vulnerable Websites
#23Re: Websmart, Inc. and 100,000 Vulnerable Websites
#24LOL http://www.websmartconsulting.com/profile.php?ClientID='
Re: Websmart, Inc. and 100,000 Vulnerable Websites
#25Re: Websmart, Inc. and 100,000 Vulnerable Websites
#26This is all fine and dandy but I actually find the approach taken by the professor in the first email to be quite unfriendly and perhaps even unprofessional. The guy from Websmart is actually right, there was no need to immediately contact his customers directly. You let the vendor handle the delicate subject with their customers and then take action directly (with a public disclosure) only if the vendor ignores you.
Any notion that a third party could threaten someone for communicating with me, or even the notion that someone should go through a third party I have given no gatekeeping-like permission to, is offensive to my basic dignity as a human being.
Re: Websmart, Inc. and 100,000 Vulnerable Websites
#27Imagine if the local news outlet did a "consumer watchdog" piece on a contractor going around installing windows or doors in homes and businesses with locks that can be easily opened without a key. Then imagine the contractor acknowledged the issue but threatened to sue the news outlet for hurting their business.
Now imagine that the local news outlet displayed a list of addresses of the homes than can be easily opened without a key. That's closer to what happened here. The disclosure was irresponsible. He could have contacted each site owner individually with information limited to their site. Instead, he sent a mass email to total strangers, putting some of them at risk, then blogged about it. That's stupid and inconsiderat…
Re: Websmart, Inc. and 100,000 Vulnerable Websites
#28I could understand if he was making a business out of this, selling improved security. But this way it just looks like he's out to show people that he knows something they don't know and publicly shame them into some kind of response.
Re: Websmart, Inc. and 100,000 Vulnerable Websites
#29- Author sends a condescending, threatening, passive-aggressive, and shaming email to a vendor and its clients.
- Vendor respectfully explains that it was an unprofessional thing to do, because their client relationships were put at risk without them having a chance to correct their mistake.
- Author completely fails to understand why the vendor would think this, and interprets the email as an effort to "intimidate [him] into silence."
To be clear, I'm not excusing the vendor for their shoddy development work. I just think this professor is clueless about effective communication.