←back to thread

561 points bearsyankees | 1 comments | | HN request time: 0.205s | source
Show context
edm0nd ◴[] No.43965336[source]
> I have been met with radio silence.

Thats when its time to inform them you are dumping the vuln to the public in 90 days due to their silence.

replies(3): >>43965359 #>>43965374 #>>43965518 #
9283409232 ◴[] No.43965359[source]
Good way to get yourself sued and have possible criminal charges brought up to you.
replies(3): >>43965376 #>>43965385 #>>43965884 #
b8 ◴[] No.43965376[source]
Which has never happened before and if it does then the EFF would back you presumably.
replies(2): >>43965442 #>>43965504 #
9283409232 ◴[] No.43965442[source]
This is a completely uninformed comment. Security researchers get sued or threatened all the time. Bunnie was threatened by Microsoft for publishing his research on Xbox vulnerabilities, the city of Columbus sued David Ross for his reporting on data exposed during a ransomware attack, Google has threatened action against a few security researchers if memory serves and that is just what I can remember off the top of my head.
replies(4): >>43965559 #>>43965722 #>>43965731 #>>43965873 #
tptacek ◴[] No.43965722[source]
I've spent my entire career doing this, have been personally "threatened" several times, and until relatively recently kept track of researchers dealing with legal threats. The concern is overblown. In cases that go beyond a nastygram from a lawyer, it is almost always the fact pattern that some aggravating factor is present: a consulting agreement that initiated the testing and forecloses disclosure, or the preservation and/or publication of the PII itself, or attempts to pivot and persist access after finding a vulnerability.

It's an especially superficial argument on this story, where the underlying vulnerability has essentially already been disclosed.

replies(1): >>43965834 #
1. secalex ◴[] No.43965834[source]
Depending on what he actually did to enumerate that database and whether he downloaded all that PII I think changes the risk profile.