Live data from Hacker News

What to do when a company refuses to fix a vulnerability I disclosed to them?

reddit.com

21–30 of 74 posts

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#22
post #5

I think you're supposed to exploit the vulnerability in relatively innocuous but deeply disturbing ways, get banned, then complain about how you only meant well, then be lauded on Hacker News as a martyr who should have been embraced by the hacked company.

Or rather you contact them. Then they ban you and possibly send the FBI after you for "illegally accessing a remote computer system" or other such crime and then you are punished for all your work. If you tell them you will disclose your research on a certain date they'll go after you for extortion.

I wrote this before and I'll say it again. I don't believe in "White Hacker" as a label. Corporations do not do well when their vulnerabilities are exposed. They don't have a way to handle "White Hackers" unless they are the ones hiring them. Most will strike back and punch you in the face no matter how good your intentions are. So if you already spent the time researching and finding the vulnerability, just disclose on a security forum or if you want to profit, sell on a black market.

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#23
post #11

From an ignorance and slightly tongue in cheek POV... ...is there a difference between discovering a new exploit and discovering a company is open to an old or well known exploit? This sounds like the latter. I'm all for disclosure of a newly found exploit because by doing so you are informing every one who might have the problem and that allows them to take action, etc. But if this is just one business who refuse to…

> I'm all for disclosure of a newly found exploit because by doing so you are informing every one who might have the problem and that allows them to take action

You also assume that it is the company that will suffer and they are the ones that have to take action. A lot of companies are public facing companies that store and maintain sensitive customer information. I thought the main reason to disclose the research is not to help the company not lose millions at the end of the quarter but to warn their customers that this company can potentially leak your information.

> Its like publishing a list of buildings that don't have good door locks or something.

It is like publishing a list of buildings that store others belongings (like a bank) that doesn't have locks on them. You want to disclose that fact because chances are someone else found the vulnerability and is exploiting it. It would actually seem very irresponsible to not disclose it in that case (after say it turns out many people's stuff goes missing).

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#24

If only the company is put in danger and they stubbornly refuse to resolve the issue, I'm not exactly sure why anyone would work so hard to convince a company to do this. The job of reporting the issue is done, a corporate decision has been made. If that decision is to remain vulnerable, as long as it does not affect users directly, why bother? Unless, as others suggested, you can legally make a profit out of it, the…

> If that decision is to remain vulnerable, as long as it does not affect users directly, why bother?

Because if that company is storing sensitive information belonging to others (emails, credit cards, etc), it would be irresponsible to not disclose it. Chances are someone else found out and has been actively exploiting that vulnerability.

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#26
post #7
post #6

Nothing. If they're unwilling to fix it, they'll end up facing the consequences when someone less scrupulous than yourself discovers it. If you do publish it, odds are they'll issue a DMCA takedown and try to sue. Speaking from experience...

If you do publish it, odds are they'll issue a DMCA takedown and try to sue. My experience is quite to the contrary. Even Intel, as poor as their security response was, didn't try to take legal action against me. (I was lucky that I was unemployed at the time, though...)

> didn't try to take legal action against me

But that is an interesting attitude. Instead of being indignant that they didn't offer to pay you for doing their security research for them ( or at least publicly thanking you) you just seem glad that they didn't sue you.

It is like volunteering to help someone and then just being glad they didn't beat you up in the end.

So it seems like there is not much benefit to doing this (there is a benefit if you prevent other people information from being stolen) but immediately there is no upside. You either get ignored or you get sued. If anyone gets sued by a company who has a full department of lawyers on retainer, it is guaranteed they'll pretty much have a bad time.

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#27
post #13
post #11

From an ignorance and slightly tongue in cheek POV... ...is there a difference between discovering a new exploit and discovering a company is open to an old or well known exploit? This sounds like the latter. I'm all for disclosure of a newly found exploit because by doing so you are informing every one who might have the problem and that allows them to take action, etc. But if this is just one business who refuse to…

Its never been legit for such burglars to gain access to a building and leave a note describing the poor security on the CEO's desk. Unless, of course, you happen to be Richard Feynman. Which most of us aren't. http://www.silvertrading.net/articles_lagniappe_01_richard_f...

I've had "Surely You're Joking" on my Kindle for almost a year now and have never read it, but every time I see anything written about Feynman I realize that I'm almost certainly missing out. He sounds like the most interesting man.
Post reply on HN