Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>Not saying they shouldn't be publicly disclosed in addition to private disclosure, but you have to give a company a fair chance to review the vulnerabilities and at least respond to you before you publish.

Why? They are the ones who let a vulnerable system onto the market. Why should I be forbidden from going public with legally obtained information when I have no contract with them? I should not share in any blame for their security vulnerabilities as I was never allowed to share it any of their profits (monetary or otherwise).



Simple ethics. If you contact them, you can at least give them time to patch the flaw for software, or time to start producing a new line of locks in this case. If you release it to the world before they're even aware of it, there's a gap where there is absolutely no mitigation whatsoever.


>If you contact them, you can at least give them time to patch the flaw for software, or time to start producing a new line of locks in this case.

Will I be paid for the effort? Or am I expected to give them information for free when they would never do the same for me? Ethics is a two way street and after superfish (among other issues) I owe this company no ethical obligations.

>If you release it to the world before they're even aware of it, there's a gap where there is absolutely no mitigation whatsoever.

Quite a convenient way to blame me for their security flaw in their product. No, this is solely on them, and as I already pointed out, they have aready burned up any professional ethical obligations.


What in the world are you talking about? How is CyberLock responsible for Superfish?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: