top | item 5733208

(no title)

nbpoole | 12 years ago

"This wouldn't happen if Yahoo had a Vulnerability Reward Program"

As much as I support these kinds of programs (https://nealpoole.com/blog/responsible-disclosure-programs/), that's a false dichotomy. Some companies have responsible disclosure policies or vulnerability reward programs. Some companies don't.

Anecdotally, the companies that do have programs don't inherently respond more quickly or handle reports better (ie: https://nealpoole.com/blog/2013/04/experiences-with-the-yand..., https://nealpoole.com/blog/2013/03/csrf-persistent-xss-in-my...). In contrast, companies that don't have programs may still be very responsive and willing to work with researchers; I reported issues to GitHub, Etsy, and Facebook before their respective programs were in place and they always responded quickly and effectively.

It comes down to the people who focus on security at the company and the way in which security is prioritized. If your company doesn't value and prioritize security, a responsible disclosure program won't make anyone's life easier.

In that sense, I do think that companies can and should do a better job of working with security researchers, regardless of whether they have a responsible disclosure program or vulnerability reward program in place. If a company takes security seriously, it should make it easy for researchers to report vulnerabilities. Researchers shouldn't feel that their reports are being sent into a black hole: if they do, they'll be less likely to spend their time reporting issues in the future.

discuss

order

simonbrown|12 years ago

Even having an email address to send reports to would be good for a lot of websites. I sometimes don't bother reporting these issues for fear of being threatened with legal action.

bluesmoon|12 years ago

you can send security reports about yahoo to security@yahoo-inc.com. All of them are addressed, and you won't be threatened with legal action. If you're lucky you might get a T-shirt.

PS: I'm an ex-paranoid. things might have changed since I left, but I'm pretty sure they'll still listen to reports.

jamespo|12 years ago

Worse than that, they may just post the vulnerabilities publicly or sell them on Black Hat forums.