Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If random security researcher does this kind of disclosure, fine.

But if serious company that seems to offer services to seemingly plenty of serious customers acts this way, I'd not want to be their customer, if they seem to have such a cavalier attitude, disclosing stuff without even a sniff of "we notified the company about the breach".



It was fixed. Disclosing it after it's fixed is responsible.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: