Earlier quoted context omitted.
Did you not consider the CEO would just lie about fixing something?
I assume the author isn't lying when they acknowledged that it had been.
That's a very common linguistical pattern.
51–60 of 157 posts
Earlier quoted context omitted.
Did you not consider the CEO would just lie about fixing something?
I assume the author isn't lying when they acknowledged that it had been.
That's a very common linguistical pattern.
Earlier quoted context omitted.
I don't think you get to call yourself polite or well-meaning when you pan them and air their shit out publicly after they respond in a way you don't like. Maybe you were superficially polite, but you do not come across as an angel. I _still_ don't know exactly what your goals are, if you're looking for acknowledgement, payment, or just trying to make the Internet a safer place for users.
Sure you do. The poster was polite, got an extremely rude response, and has no obligation to be polite afterwards. Airing their shit out is a disclosure of a vulnerability, and it's important to do. Typically you reach out to say, "how would you prefer I do this?" And work through a common understanding. The company flipped the bird, so it got aired very publicly.
Their behavior when things don't go their way belies their initial "politeness". When the transaction didn't go how they wanted, they pulled the trigger on being a dick, publicly. That is a much worse offense that an impolite email. If this were a coworker or a contractor, it would color all of my interactions with them going forward.
Earlier quoted context omitted.
Step 6 happened because the CEO in his hubris, decided it would be in his best interests to threaten someone instead of being greatful. Additionally, had the CEO responded appropriately and followed the standard methodology of all reasonable bug bounty programs, it would have included a request for the researcher to verify the fix and that there are no additional related bugs or defects with the current patch. You no…
I'm wondering how it's possible that step 6 happened, not what the motivations are. It's written in multiple places as if database queries were issued after the database was taken down.
Earlier quoted context omitted.
That's...not what blackmail is. Blackmail is when someone says "do $thing or else". That didn't happen here, implicitly or explicitly. If you're saying the implicit blackmail was "don't be an asshole, or else I'll be unkind when I talk about you later to others", then all of us are always blackmailing one another with every conversation.
Yes, "it would be a shame if something were to happen" is also not extortion, because you aren't actually saying you will visit misery upon them, only implying it. The mistake you are making is assuming the researcher wants literally nothing, or that the CEO can know they want literally nothing. I still have no idea what they actually wanted, and whether there was going to be some sort of value extraction.
Earlier quoted context omitted.
If you know the secret to getting a company to prioritize potential security problems that haven't yet emerged in forty years over meeting payroll, please share.
why does it sound like you're defending the argument of; I couldn't act ethically because I had to make money.
Earlier quoted context omitted.
I told him everything he needed to know to fix the exposure on my initial contact on the exact same email I tell him I'm not asking for anything. I even told him some information about the exposed tables. Backed by the fact that 1 hour after my email, the exposure was closed and the company never replied back to me, it was only after I followed up they emailed all those claims. Again, I never asked for anything, I ev…
[flagged]
It may be shocking to you, but some security researchers notify companies when they are exposing data of their customers. That's it! Simple.
When I notice that thousands of people's personal information is available, I also will email the company and let them know that they are exposing the information of their customers. I don't want money in return. My hobby is security, my payment is knowing that I helped thousands of people out.
>I would NOT be happy to receive such an email.
You would rather just continue to expose your customer's information? Interesting... I don't think you have the ethical high ground here, if that is your position.
Earlier quoted context omitted.
I told him everything he needed to know to fix the exposure on my initial contact on the exact same email I tell him I'm not asking for anything. I even told him some information about the exposed tables. Backed by the fact that 1 hour after my email, the exposure was closed and the company never replied back to me, it was only after I followed up they emailed all those claims. Again, I never asked for anything, I ev…
[flagged]
I'm not sure what you find ambiguous or confusing.
Earlier quoted context omitted.
Step 6 happened because the CEO in his hubris, decided it would be in his best interests to threaten someone instead of being greatful. Additionally, had the CEO responded appropriately and followed the standard methodology of all reasonable bug bounty programs, it would have included a request for the researcher to verify the fix and that there are no additional related bugs or defects with the current patch. You no…
I'm wondering how it's possible that step 6 happened, not what the motivations are. It's written in multiple places as if database queries were issued after the database was taken down.
Earlier quoted context omitted.
I told him everything he needed to know to fix the exposure on my initial contact on the exact same email I tell him I'm not asking for anything. I even told him some information about the exposed tables. Backed by the fact that 1 hour after my email, the exposure was closed and the company never replied back to me, it was only after I followed up they emailed all those claims. Again, I never asked for anything, I ev…
[flagged]