> Instead, I offered to sign a modified declaration confirming data deletion. I had no interest in retaining anyone’s personal data, but I was not going to agree to silence about the disclosure process itself. Why sign anything at all? The company was obviously not interested in cooperation, but in domination.
[flagged]
I found a vulnerability. they found a lawyer
31–40 of 466 posts
Re: I found a vulnerability. they found a lawyer
#32Wish they named them. Usually I don't recommend it. But the combination of: A) in EU; GDPR will trump whatever BS they want to try B) no confirmation affected users were notified C) aggro threats D) nonsensical threats, sourced to Data Privacy Officer w/seemingly 0 scruples and little experience Due to B), there's a strong responsibility rationale. Due to rest, there's a strong name and shame rationale. Sort of equiv…
Re: I found a vulnerability. they found a lawyer
#33Earlier quoted context omitted.
[flagged]
Because you are highjacking a thread. Wanna trash the site's design, you should open a top level thread instead.
Or better, don't[1]:
Please don't complain about tangential annoyances—e.g. article or website formats, name collisions, or back-button breakage. They're too common to be interesting.
Re: I found a vulnerability. they found a lawyer
#34Earlier quoted context omitted.
[flagged]
Your response didn’t have anything to do with the parent comment. And I’m on a phone (iOS) and had no issue reading it, for the record.
If it was a random JS error, well, that reminds me of: https://www.kryogenix.org/code/browser/everyonehasjs.html
Re: I found a vulnerability. they found a lawyer
#35This is an LLM-generated article, for anyone who might wish to save the "15 min read" labelled at the top. Recounts an entirely plausible but possibly completely made up narrative of incompetent IT, and contains no real substance.
The same could be said of the accusation being levied here.
Re: I found a vulnerability. they found a lawyer
#36Based on this interaction, you have wonder what it's like to file a claim with them.
Re: I found a vulnerability. they found a lawyer
#37Re: I found a vulnerability. they found a lawyer
#38This is an LLM-generated article, for anyone who might wish to save the "15 min read" labelled at the top. Recounts an entirely plausible but possibly completely made up narrative of incompetent IT, and contains no real substance.
HN's comment section new favourite sport, trying to guess if an article was generated by LLM. It's completely pointless. Why not focus on what's being said instead?
Re: I found a vulnerability. they found a lawyer
#39Another comment says the situation was fake. I don't know, but to avoid running afoul of the authorities, it's possible to document this without actually accessing user data without permission. In the US, the Computer Fraud and Abuse Act and various state laws are written extremely broadly and were written at a time when most access was either direct dial-up or internal. The meaning of abuse can be twisted to mean re…
Re: I found a vulnerability. they found a lawyer
#40I think the problem is the process. Each country should have a reporting authority and it should be the one to deal with security issues. So you never report to actual organization but to the security organization, like you did. And they would be more equiped to deal with this, maybe also validate how serious this issue is. Assign a reward as well. So you are researcher, you report your thing and can't be sued or bul…
Right now the climate in the world is whistleblowers get their careers and livihoods ended. This has been going on for quite a while.
The only practical advice is ignore it exists, refuse to ever admit to having found a problem and move on. Leave zero paper trail or evidence. It sucks but its career ending to find these things and report them.