Live data from Hacker News

What to do when a company refuses to fix a vulnerability I disclosed to them?

reddit.com

61–70 of 74 posts

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#61
post #39
post #22

Earlier quoted context omitted.

Or rather you contact them. Then they ban you and possibly send the FBI after you for "illegally accessing a remote computer system" or other such crime and then you are punished for all your work. If you tell them you will disclose your research on a certain date they'll go after you for extortion. I wrote this before and I'll say it again. I don't believe in "White Hacker" as a label. Corporations do not do well wh…

If you tell them that unless they pay you or retain you as a contractor by a certain date that you'll publish, you are in fact extorting them. People who have found vulnerabilities and also been naive about the law have run aground on this before.

Do you have any examples?

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#62

Seems pretty straightforward to me -- since it's a DoS that doesn't put users' information at risk, just publish it without naming the company.

That's the first sensible and ethical suggestion in this thread.

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#63
He could just leave them alone and do nothing. It's their service and if they don't want to respond then let them leave the vulnerability open. It doesn't affect user privacy so there is no duty to fellow users as there is in some other cases where a vulnerability being left open means people could be losing private information on an ongoing basis.

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#64
post #39

Earlier quoted context omitted.

If you tell them that unless they pay you or retain you as a contractor by a certain date that you'll publish, you are in fact extorting them. People who have found vulnerabilities and also been naive about the law have run aground on this before.

Do you have any examples?

I'm worried that if I start Googling this I'll lose a couple hours of my day to a "researching vulnerability extortion" jag.

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#65
post #48

If only the company is put in danger and they stubbornly refuse to resolve the issue, I'm not exactly sure why anyone would work so hard to convince a company to do this. The job of reporting the issue is done, a corporate decision has been made. If that decision is to remain vulnerable, as long as it does not affect users directly, why bother? Unless, as others suggested, you can legally make a profit out of it, the…

It appears he wants to publish the vulnerability (might be a novice security researcher) without getting sued.

He is very, very unlikely to be sued provided that (i) he didn't explicitly agree to a contract forbidding security research when he acquired the application, (ii) he acquired the application lawfully, (iii) he at no point solicited business from the vendor of the application, (iv) he didn't exploit the vulnerability in any way that could be construed as having caused direct damages to the vendor, and (v) he is scrupulously honest and careful about how he writes the finding up.

Contrary to popular opinion on HN, finding vulnerabilities in software you yourself run on your own computer is rarely fraught. We hear about the exceptions in the news because they're exceptional. In reality, people publish vulnerabilities all the time.

The same thing obviously CANNOT BE SAID about finding vulnerabilities in other people's web applications. Finding web vulnerabilities without permission is highly fraught. You can easily find yourself both civilly and criminally liable for doing so.

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#66
post #44

I'm curious what we could change legally to make this less an issue. There's a clear conflict of interest between doing a public good by disclosing a vulnerability and not wanting to risk (at worst) the FBI coming after you or (at best) losing clients. I would certainly consider it unethical to know of a vulnerability and not disclose that information publicly, but there are so many hurdles to doing so that I don't b…

The FBI is not going to come after you for publishing a DOS vulnerability in a mobile app; in fact, you could find and publish remote code execution in an extremely popular application (say Instagram or Twitter) without even telling the vendor and still not be in any trouble. People do it all the time.

Most of the stories you hear about people getting in actual trouble over vulnerability research involve web vulnerabilities. You cannot hack someone else's web site to make a point, even if the underlying point is unimpeachable ("this application is insecure and people should know about it").

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#67
post #22

Earlier quoted context omitted.

Or rather you contact them. Then they ban you and possibly send the FBI after you for "illegally accessing a remote computer system" or other such crime and then you are punished for all your work. If you tell them you will disclose your research on a certain date they'll go after you for extortion. I wrote this before and I'll say it again. I don't believe in "White Hacker" as a label. Corporations do not do well wh…

I believe you mean "White Hat Hacker"... I think everyone gets the gist of what you mean but just wanted to clarify in case someone's thinking you're a racist hating on "Whitie" or something :)

Are there really people in this community who don't know this?

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#68

Earlier quoted context omitted.

I believe you mean "White Hat Hacker"... I think everyone gets the gist of what you mean but just wanted to clarify in case someone's thinking you're a racist hating on "Whitie" or something :)

Are there really people in this community who don't know this?

I've heard the phrase "white hat" used frequently to describe hackers. I've never heard the phrase "white hacker".

  About 526,000 results
  http://www.google.com/#hl=en&q=%22white+hat%22+hacker

  About 65,000 results
  http://www.google.com/search?hl=en&q=%22white%20hacker%22

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#69
The linked post is talking about a DoS vulnerability of the service. It doesn't impact other entities than the service provider (beyond the obvious potential for service outage of its users). I think telling them about it is all that's required. Either they fix it or they don't, that's between them and their users.

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#70
post #22

Earlier quoted context omitted.

Or rather you contact them. Then they ban you and possibly send the FBI after you for "illegally accessing a remote computer system" or other such crime and then you are punished for all your work. If you tell them you will disclose your research on a certain date they'll go after you for extortion. I wrote this before and I'll say it again. I don't believe in "White Hacker" as a label. Corporations do not do well wh…

I believe you mean "White Hat Hacker"... I think everyone gets the gist of what you mean but just wanted to clarify in case someone's thinking you're a racist hating on "Whitie" or something :)

Sorry, of course you are right. And it is too late to 'edit' the comment. Thanks for pointing it out.
Post reply on HN