6 ms·
> Indeed, especially when Googling "Mercedes report security issue" the page litterally populates the results with the address to email so it wasn't like it's h
by _kbh_ 3y ago
> Indeed, especially when Googling "Mercedes report security issue" the page litterally populates the results with the address to email so it wasn't like it's hard to find.
Reporting via a third party isn't super unusual if you think that a organisation may be a bit legal threat happy from your report.
- waihtis 3y agoThis may be true if there isn't a vulnerability disclosure program in place but there was, thus your point is completely invalid.
- hug 3y agoNo, his point remains: companies may act in bad faith, and publicly committing to act in good faith is absolutely no evidence they will not. I don’t mean to be trite, but publishing a bug bounty program doesn’t mean you’re the good guys.
- waihtis 3y ago> publishing a bug bounty program doesn’t mean you’re the good guys this is meaningless rabble. Yes you can get burned in all kinds of legitimate situations [1], but 99.xx% of bug bounty interactions do not result in any kind of legal action even if you wander a bit out of scope [1]: https://eu.desmoinesregister.com/story/news/crime-and-courts/2021/08/01/arrested-coalfire-security-testers-2019-file-dallas-county-iowa-courthouse-lawsuit/5431611001/ https://eu.desmoinesregister.com/story/news/crime-and-courts...