▲ | robswc a day ago | |||||||
Reminds me of a time I found a serious issue with mailgun. Messaged them, no reply. Had to spam their twitter to get a response. Basically you could have stolen tons of API keys from users without their knowledge and mailgun never disclosed it. I could have actually gone to their office in person if I wanted to be pedantic but it actually seemed like a pretty weird office space lol. | ||||||||
▲ | tptacek a day ago | parent [-] | |||||||
I don't think disclosure of reported security issues is really a norm, unless the firm finds evidence the bug was exploited (by someone other than the reporter). It's a good thing to do, but I think the majority of stuff that gets reported everywhere is never disclosed --- with the major and obvious exception of consumer or commercial software that needs to be updated "on prem". | ||||||||
|