Since the author is apparently afraid to name the organisation in question, it seems the legal threats have worked perfectly.
I found a vulnerability. they found a lawyer
81–90 of 466 posts
Re: I found a vulnerability. they found a lawyer
#82I think the problem is the process. Each country should have a reporting authority and it should be the one to deal with security issues. So you never report to actual organization but to the security organization, like you did. And they would be more equiped to deal with this, maybe also validate how serious this issue is. Assign a reward as well. So you are researcher, you report your thing and can't be sued or bul…
That’s almost what we already have with the CVE system, just without the legal protections. You report the vulnerability to the NSA, let them have their fun with it, then a fix is coordinated to be released much further down the line. Personally I don’t think it’s the best idea in the world, and entrenching it further seems like a net negative.
Re: I found a vulnerability. they found a lawyer
#83When you are acting in good faith and the person/organization on the other end isn't, you aren't having a productive discussion or negotiation, just wasting your own time. The only sensible approach here would have been to cease all correspondence after their very first email/threat. The nation of Malta would survive just fine without you looking out for them and their online security.
Re: I found a vulnerability. they found a lawyer
#84Since the author is apparently afraid to name the organisation in question, it seems the legal threats have worked perfectly.
Re: I found a vulnerability. they found a lawyer
#85This is an LLM-generated article, for anyone who might wish to save the "15 min read" labelled at the top. Recounts an entirely plausible but possibly completely made up narrative of incompetent IT, and contains no real substance.
Your firebrand attitude is doing a disservice to everyone who takes vibe hunting vibecraft seriously!
The intended audience doesn’t even care that this is LLM-assisted writing. Whether the narrative is affected by AI is second to the technical details. This is technical documentation communicated through a narrative, not personal narrative about someone’s experience with a technical problem. There’s a difference!
What are you in this for?!
Re: I found a vulnerability. they found a lawyer
#86This sounds like a cultural mismatch with their lawyers. Which is ironic, since the lawyers in question probably thought of themselves as being risk-averse and doing everything possible to protect the organisation's reputation.
Re: I found a vulnerability. they found a lawyer
#87Since the author is apparently afraid to name the organisation in question, it seems the legal threats have worked perfectly.
Or maybe in the diving community, "Maltese insurance company for divers" is about as subtle as "Bird-themed social network with blue checkmarks".
https://www.reddit.com/r/scuba/comments/1r9fn7u/apparently_a...
Re: I found a vulnerability. they found a lawyer
#88Earlier quoted context omitted.
Or maybe in the diving community, "Maltese insurance company for divers" is about as subtle as "Bird-themed social network with blue checkmarks".
I'm a diver, DAN is the only company I can name that specialises in diving insurance. Huh, apparently they're registered in Malta, what a coincidence...
[0]: https://www.perplexity.ai/search/maltese-scuba-diving-insura...
Re: I found a vulnerability. they found a lawyer
#89I’ve worked in I.T. For nearly 3 decades, and I’m still astounded by the disconnect between security best practices, often with serious legal muscle behind them, and the reality of how companies operate. I came across a pretty serious security concern at my company this week. The ramifications are alarming. My education, training and experience tells me one thing: identify, notify, fix. Then when I bring it to leader…
> These are the sort of things that are supposed to lead to commendations and promotions. Maybe I live in fantasyland. I had a bit of a feral journey into tech, poor upbringing => self taught college dropout waiting tables => founded iPad point of sale startup in 2011 => sold it => Google in 2016 to 2023 It was absolutely astounding to go to Google, and find out that all this work to ascend to an Ivy League-esque emp…
Maybe not when it is as much as 20 seconds, but an old manager of mine would save fixing something like that for a “quick win” at some later time! He would even have artificial delays put in, enough to be noticeable and perhaps reported but not enough to be massively inconvenient, so we could take them out during the UAT process - it didn't change what the client finally got, but it seemed to work especially if they thought they'd forced us to spend time on performance issues (those talking to us at the client side could report this back up their chain as a win).
Re: I found a vulnerability. they found a lawyer
#90I’ve worked in I.T. For nearly 3 decades, and I’m still astounded by the disconnect between security best practices, often with serious legal muscle behind them, and the reality of how companies operate. I came across a pretty serious security concern at my company this week. The ramifications are alarming. My education, training and experience tells me one thing: identify, notify, fix. Then when I bring it to leader…
> By even flagging the issue and the potential fallout, I’ve put my career at risk. Simple as. Not your company? not your problem? Notify, move on.
For an external company “not your company, not your problem” for security issues is not a good moral position IMO. “I can't risk the fallout in my direction that I'm pretty sure will result from this” is more understandable because of how often you see whistle-blowers getting black-listed, but I'd still have a major battle with the pernickety prick that is my conscience¹ and it would likely win out in the end.
[1] oh, the things I could do if it wasn't for conscience and empathy :)