Earlier quoted context omitted.
For the researcher? Because the vendor has a responsible disclosure program. Because they'd rather know about the bugs. (As for the vendor, I'm sympathetic to the argument that there should be vendor liability under some circumstances.)
In Germany it is common for vendors to acknowledge the security flaw you send to them, but if you want to publish it (and damage their reputation by doing so) they are going to try you in court, and win. Sometimes they even try you in court if you don't publish it (yet)
Hacking millions of modems and investigating who hacked my modem
71–80 of 282 posts
Re: Hacking millions of modems and investigating who hacked my modem
#72Earlier quoted context omitted.
agreed, lets hope they dont bloody sue him into the ground for "hacking" Its stuff like this that company's should REWARD people for finding.
I assumed they offered a bounty for bug disclosure? You mean to tell me that an internet provider with 11 billion in revenue can't pay someone that found a bug impacting all their clients? Frankly he could have just sold the vulnerability to the highest bidder
> Cox does not offer a bounty program or provide compensation in exchange for security vulnerability submissions.
https://www.cox.com/aboutus/policies/cox-security-responsibl...
Re: Hacking millions of modems and investigating who hacked my modem
#73Earlier quoted context omitted.
agreed, lets hope they dont bloody sue him into the ground for "hacking" Its stuff like this that company's should REWARD people for finding.
I assumed they offered a bounty for bug disclosure? You mean to tell me that an internet provider with 11 billion in revenue can't pay someone that found a bug impacting all their clients? Frankly he could have just sold the vulnerability to the highest bidder
This attitude is why "independent security researchers" offering to present unsolicited findings to companies in exchange for payment feels exactly like extortion.
Re: Hacking millions of modems and investigating who hacked my modem
#74Earlier quoted context omitted.
agreed, lets hope they dont bloody sue him into the ground for "hacking" Its stuff like this that company's should REWARD people for finding.
I assumed they offered a bounty for bug disclosure? You mean to tell me that an internet provider with 11 billion in revenue can't pay someone that found a bug impacting all their clients? Frankly he could have just sold the vulnerability to the highest bidder
Why? Ethics aside, is everything money?
Re: Hacking millions of modems and investigating who hacked my modem
#75> After reporting the vulnerability to Cox, they investigated if the specific vector had ever been maliciously exploited in the past and found no history of abuse Would you trust a thing they say? It seems their whole network is swiss cheese.
Re: Hacking millions of modems and investigating who hacked my modem
#76Re: Hacking millions of modems and investigating who hacked my modem
#77Earlier quoted context omitted.
I assumed they offered a bounty for bug disclosure? You mean to tell me that an internet provider with 11 billion in revenue can't pay someone that found a bug impacting all their clients? Frankly he could have just sold the vulnerability to the highest bidder
> Frankly he could have just sold the vulnerability to the highest bidder Why? Ethics aside, is everything money?
Re: Hacking millions of modems and investigating who hacked my modem
#78Did you determine if POSTs were replayed? As in, logging into accounts and sending payment info and account info?
Re: Hacking millions of modems and investigating who hacked my modem
#79What sort of authentication system just lets calls through randomly sometimes... The incompetence!
Re: Hacking millions of modems and investigating who hacked my modem
#80What does this mean?