Live data from Hacker News

Ask HN: Maybe found huge security problem, unsure what to do

news.ycombinator.com

51–52 of 52 posts

Re: Ask HN: Maybe found huge security problem, unsure what to do

#51
post #10
post #4

When it comes to vulnerability reporting and/or disclosure, there are two schools of thought; "responsible disclosure" and "full disclosure". Unfortunately, what "full disclosure" and "responsible disclosure" actually mean can vary a whole lot. For example, some define "full disclosure" as immediately publishing/disclosing the vulnerability and/or with working exploit code, but more level-headed folks define "full di…

Thank you so much for this. (xpto123 as well). I tried calling but just got bounced around and I'm not sure anyone actually understood/cared. I've got a nice early season cold going so not really interested in sitting on the phone for hours so I've given up on that. I'm going to email blast as many of the emails I can get and if I don't hear anything back from them by Monday I'll pass it onto CERT.

All of this should be done in an anonymous way: I would say just create an anonymous gmail and open an anonymous linkedin account. Hit the same invitation message to a list of persons that work there, and really don't think about it anymore.

The law is not on your side in most countries, there are honest security researchers in jail for doing things like this, so beware of your personal safety at all times.

If you already identified yourself and followed their security submission page and they did not follow up, then its best to leave it at that. Above all don't get in personal trouble because of this, it's not worth it.

Re: Ask HN: Maybe found huge security problem, unsure what to do

#52

With all due respect, most of the replies here are missing the most important point. Does the company have a bug bounty policy? No? Then keep your mouth shut and get on with your life . A significant percentage of people in power will react to unsolicited warnings of security vulnerabilities by attacking you as though you were their enemy. Worse, the law is at least not clearly on your side. This is not theoretical:…

The answer is not "sweep the problem under the rug", but rather "tell people who know what theyre doing". The idea of "oh lets just pretend this security hole doesnt exist" makes me cringe. As JCR wrote: "The safe and sane approach is to contact CERT [3,4] through their vulnerability reporting page [5] and let them contact the vendor." [4] https://www.cert.org [5] http://www.kb.cert.org/vuls/html/report-a-vulnerabili…

If that idea makes you cringe, you should work to change our politicians because that is how the law is written. Any unauthorized access, even if the initial probe was accidental, is against the law and with the way security break-ins hurt company stock prices these days, you can be damn sure someone will come after you if it gets out, even if you weren't the one to release it.

All-in-all, don't tell people unless you have explicit, written proof of the companies consent to pentest their application because its simply not worth risking your entire life because someone in power's day is ruined by your curiosity.

Post reply on HN