Earlier quoted context omitted.
Well, mostly because if it was good enough, it would be the first thing out of the mouth of every blackhat that was caught... Or to put it in a slightly more nuanced fashion, as a blackhat I could compromise your system, and then turn around and inform you that your system was being compromised whilst at the same time profiting from any data I had already stolen . If the company being contacted does not personally kn…
> Or to put it in a slightly more nuanced fashion, as a blackhat I could compromise your system, and then turn around and inform you that your system was being compromised whilst at the same time profiting from any data I had already stolen . Which provides a perfectly reasonable way to distinguish the white hat from the black hat. The black hat is the one making fraudulent charges to stolen credit cards, or selling…
Well no, not really. After all, the blackhat isn't telling you that they're also busy selling your data to someone. And even if you are aware that the data is being sold, the blackhat can claim that it must be another intruder using the same flaw, and geez, you really should fix that!