Imagine if the local news outlet did a "consumer watchdog" piece on a contractor going around installing windows or doors in homes and businesses with locks that can be easily opened without a key. Then imagine the contractor acknowledged the issue but threatened to sue the news outlet for hurting their business.
Websmart, Inc. and 100,000 Vulnerable Websites
11–20 of 74 posts
Re: Websmart, Inc. and 100,000 Vulnerable Websites
#12Contact the vendor, give them time to fix it. Wtf are your contacting his customers? Sam, you are truly a moron.
It doesn't seem that he felt like taking any action since 2010
Re: Websmart, Inc. and 100,000 Vulnerable Websites
#13Contact the vendor, give them time to fix it. Wtf are your contacting his customers? Sam, you are truly a moron.
It doesn't seem that he felt like taking any action since 2010
Re: Websmart, Inc. and 100,000 Vulnerable Websites
#14I appreciate that the guy's attitude is just awful, but the author really should have given him a chance to respond/react before contacting his clients. Doing so doesn't preclude notifying them eventually. It's just common courtesy.
Re: Websmart, Inc. and 100,000 Vulnerable Websites
#15Re: Websmart, Inc. and 100,000 Vulnerable Websites
#16Imagine if the local news outlet did a "consumer watchdog" piece on a contractor going around installing windows or doors in homes and businesses with locks that can be easily opened without a key. Then imagine the contractor acknowledged the issue but threatened to sue the news outlet for hurting their business.
Now imagine that the local news outlet displayed a list of addresses of the homes than can be easily opened without a key. That's closer to what happened here. The disclosure was irresponsible. He could have contacted each site owner individually with information limited to their site. Instead, he sent a mass email to total strangers, putting some of them at risk, then blogged about it. That's stupid and inconsiderat…
Re: Websmart, Inc. and 100,000 Vulnerable Websites
#17This is all fine and dandy but I actually find the approach taken by the professor in the first email to be quite unfriendly and perhaps even unprofessional. The guy from Websmart is actually right, there was no need to immediately contact his customers directly. You let the vendor handle the delicate subject with their customers and then take action directly (with a public disclosure) only if the vendor ignores you.
This would only makes sense if the vendor didn't care. But even then its a long uphill battle.
Re: Websmart, Inc. and 100,000 Vulnerable Websites
#18LOL http://www.websmartconsulting.com/profile.php?ClientID='
Re: Websmart, Inc. and 100,000 Vulnerable Websites
#19LOL http://www.websmartconsulting.com/profile.php?ClientID='
Re: Websmart, Inc. and 100,000 Vulnerable Websites
#20Earlier quoted context omitted.
It doesn't seem that he felt like taking any action since 2010
Are you sure he was notified in those previous incidents? Sure, that's really poor behavior of the company, but you don't know if he was even aware. Sam should have responsibly disclosed the information assuming that it was not already known - his actions were indeed unprofessional and could've been approached differently - if there was still no action taken, then that's a whole other story.