8 ms·
When I see security vulnerabilities I rarely get involved because the party with the vulnerability will become suspicious of you. It's not worth the hassle.
by va_coder 15y ago
When I see security vulnerabilities I rarely get involved because the party with the vulnerability will become suspicious of you. It's not worth the hassle.
- delinka 15y agoIt's this kind of reaction that makes our technological toys less secure. It's this kind of reaction that the Ominous Large Corporation wants us to have. The standard belief is as follows: being proactive about privacy and security costs money, and if we don't have to spend money we won't. Most people, the ones we're crowdsourcing or selling to advertisers, don't understand and won't care who actually screwed up - we'll blame the hackers and that will limit negative perceptions.
- jellicle 15y agoThis is certainly the correct approach to take individually. Advantage to you of trying to disclose the flaw: zero in most cases. Disadvantage to you of trying to disclose the security flaw: possibly years in jail, hundreds of thousands of dollars spent. It's unfortunate that this is true, but it's true nonetheless. The country needs a Computer Good Samaritan law, where those who follow a prescribed process for flaw disclosure are granted complete immunity from prosecution, civil suits and general harassment.