Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I can't blame Titanous under these circumstances, though.

It's a whole different ballgame when you're testing applications under contract (as I know you know), but as a budding researcher/security guy, it might be better for him to publish via responsible disclosure (as he did just now) than to accept a temporary (presumably secret) contract.

I know that ethical disclosure is a whole can of worms that isn't completely relevant to this conversation, but I'm a firm believer that Titanous went about this the right way. First off, he is the customer (as a Heroku user), and secondly he notified Heroku and waited until the vulnerability was fixed before publishing his findings. If all researchers behaved in such a responsible way, we'd probably be in a better place as an industry.

Anyway, the point I'm making is that, sure, having a penetration testing contract with Heroku might have been nice for his career, but I think being able to point to this research that he's conducted on his own and responsibly disclosed is far better. Hell, I'd offer him a job right now if he seemed interested.



I hope it doesn't sound like I'm blaming him for anything. I'm not.


I do not think your post reads out as blaming Jonathan/Titanous. But David's post is a valuable addition - especially the possible personal marketing side of the publication.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: