top | item 36254297

(no title)

Demmme | 2 years ago

Black hat vs white hat.

As soon as I would discover I could do that, I would inform the company not some scritkiddies on the internet.

This is just irresponsible

discuss

order

TeMPOraL|2 years ago

> This is just irresponsible

And reporting to the vendor is suicidal. At least assuming the stories I hear about vulnerability disclosures are representative, which I think they are.

In their place, if I were to inform the company, I'd do it anonymously. If it was an actually important issue - as this very much looks like - I'd consider informing the building manager, HOA, the gas installation company they use, and every local journalist, all together so they know about each other - and then CC that to the vendor.

tgsovlerkhgsel|2 years ago

Another option can be your country's CERT. In reasonably developed countries they generally have competent enough people to understand the concept of responsible disclosure (i.e. won't try to harass you for doing a good thing), and if they realize "oh shit, this is a critical infrastructure risk" they're probably in the best position to address not just the specific case, but also drive improvements (including via regulation) across vendors.

nextlevelwizard|2 years ago

How often have we seen good intentions be punished?

Demmme|2 years ago

More often than not.

I don't buy this and will not act shitty just because