Live data from Hacker News

What to do when a company refuses to fix a vulnerability I disclosed to them?

reddit.com

1–10 of 74 posts

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#2
There are security companies that buy these kind of information from you (like antivirus companies), so that they can patch the breaches themselves and proudly announce they discovered a breach and only by using their software you can be protected.

I don't know how legal it is, and I understand that the breach finder wants to publish his findings himself (for "reputations points" maybe ?), and he might lose this right by selling an info, but at least he's getting something out of this. IANAL, but i'm pretty sure you could get in trouble for publicly posting information on how to hack a public service (or pretty much anything for that matter)

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#3
If only the company is put in danger and they stubbornly refuse to resolve the issue, I'm not exactly sure why anyone would work so hard to convince a company to do this. The job of reporting the issue is done, a corporate decision has been made. If that decision is to remain vulnerable, as long as it does not affect users directly, why bother?

Unless, as others suggested, you can legally make a profit out of it, then by all means! Otherwise, just let it go...

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#5
I think you're supposed to exploit the vulnerability in relatively innocuous but deeply disturbing ways, get banned, then complain about how you only meant well, then be lauded on Hacker News as a martyr who should have been embraced by the hacked company.

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#7
post #6

Nothing. If they're unwilling to fix it, they'll end up facing the consequences when someone less scrupulous than yourself discovers it. If you do publish it, odds are they'll issue a DMCA takedown and try to sue. Speaking from experience...

If you do publish it, odds are they'll issue a DMCA takedown and try to sue.

My experience is quite to the contrary. Even Intel, as poor as their security response was, didn't try to take legal action against me. (I was lucky that I was unemployed at the time, though...)

Re: What to do when a company refuses to fix a vulnerability I disclosed to them?

#8
If you contacted them non-anonymously first, you made a mistake, because they can and will sue you if you disclose it. Judges don't understand computers and US courts are all about draining money from someone, so they still might ruin you out of spite even if you disclose it in a way that there's no proof it was you or if someone else who discovered and released it on his own.

The correct way would be: 1) discover a vulnerability 2) contact them anonymously 3) if they don't fix it, anonymuosly release it to general public

That way, you can still help them while protecting yourself. The third step is optional of course.

Post reply on HN