North American Network Operators Group|
Date Prev | Date Next |
Date Index |
Thread Index |
Author Index |
Re: UK ISP threatens security researcher
- From: Leigh Porter
- Date: Tue Apr 24 06:59:03 2007
Dragos Ruiu wrote:
On Thursday 19 April 2007 18:25, Simon Lyall wrote:Yeah but in this case the company the bug was being reported to
deliberately setup this back door password and had previously ignored
people bringing it to their attention. There is a point where, as you
say, their being ignorant idiots takes over.
If you are a random person who comes across a security hole in a website
or commercial product then the best thing to do is tell nobody, refrain
from any further investigation and if possible remove all evidence you
ever did anything.
There is almost zero potential upside of reporting these holes vs the very
real potential downside that the company might decide to go after you with
their legal team or the police.
And when we start propagating messages like this, it will be bad news.
Just report the bug. Unless they are ignorant idiots they should thank
you in some way.
So what do you do then? Yer damned if you do and everybody's pwned if