| ▲ | menomatter an hour ago | |||||||||||||
Speaking of being sue, I once found a hole in a healthcare system. I solicited legal advice and the response was overwhelmingly against reporting. The company didn’t not have a bounty program. So I shut up knowing my info is sitting there exposed. I wonder what’s the consensus on this? Do people normally report it or not? On some forms I was advised to report hippa complaint. I can’t remember if I did. This was 10 or more years ago. | ||||||||||||||
| ▲ | SahAssar 38 minutes ago | parent | next [-] | |||||||||||||
I think my take would be to report it anonymously (via support/marketing/etc.) and in the report strongly encourage them to create a path for security reports (either via a bounty or just a security email). When fixed or actually dismissed post publicly on anonymous channels, with a section saying how they could have created a channel for these reports. | ||||||||||||||
| ▲ | john_strinlai an hour ago | parent | prev [-] | |||||||||||||
>Do people normally report it or not? if you are reporting it for moral/ethical reasons, but are worried that the company will have a shitty response, report it anonymously to the company and any relevant regulatory bodies. but most companies, even without a bounty program, are happy to receive reports. a lack of a bounty program isn't really an indicator of how they will treat reporters, as most companies are ill-equipped to have a proper bounty program. otherwise, and i know this is an unpopular opinion here, but i'm a big advocate of just posting the exploit publicly when a company makes it hard/scary to report it to them. | ||||||||||||||
| ||||||||||||||