Live data from Hacker News

What to do when a company refuses to fix a vulnerability I disclosed to them?

reddit.com

71–74 of 74 posts

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#71
post #68

Earlier quoted context omitted.

Are there really people in this community who don't know this?

I've heard the phrase "white hat" used frequently to describe hackers. I've never heard the phrase "white hacker". About 526,000 results http://www.google.com/#hl=en&q=%22white+hat%22+hacker About 65,000 results http://www.google.com/search?hl=en&q=%22white%20hacker%22

You know what? I totally mentally replaced the word "white hacker" with "white hat", and only realized it after you pointed it out.

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#72
post #65
post #48

Earlier quoted context omitted.

It appears he wants to publish the vulnerability (might be a novice security researcher) without getting sued.

He is very, very unlikely to be sued provided that (i) he didn't explicitly agree to a contract forbidding security research when he acquired the application, (ii) he acquired the application lawfully, (iii) he at no point solicited business from the vendor of the application, (iv) he didn't exploit the vulnerability in any way that could be construed as having caused direct damages to the vendor, and (v) he is scrup…

I would adjust "other people's web applications" to be "in other people's deployments."

For example, it is fine to take someone else's commercial web app, install it on your own server, and beat it up.

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#73
post #65

Earlier quoted context omitted.

He is very, very unlikely to be sued provided that (i) he didn't explicitly agree to a contract forbidding security research when he acquired the application, (ii) he acquired the application lawfully, (iii) he at no point solicited business from the vendor of the application, (iv) he didn't exploit the vulnerability in any way that could be construed as having caused direct damages to the vendor, and (v) he is scrup…

I would adjust "other people's web applications" to be "in other people's deployments." For example, it is fine to take someone else's commercial web app, install it on your own server, and beat it up.

That is a good point, thanks for amending.
Post reply on HN