• mermella@piefed.social
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    5
    ·
    9 hours ago

    Against best practice of informing the company first to remediate. Now it’s a security nightmare for anyone running it locally

    • bss03@infosec.pub
      link
      fedilink
      English
      arrow-up
      5
      ·
      5 hours ago

      Once companies started suing people trying to practice “responsible disclosure”, I stopped attacking people that choose maximum disclosure.

      Responsible disclosure has always been a bit of a hedge. It’s rare to be able to show you are actually the first person/organization to discover a vulnerability.