Hacker News new | ask | show | jobs
by vellum 3345 days ago
CERT and the Zero Day Initiative handle disclosure for you, in some cases.

https://vulcoord.cert.org/VulReport/ http://www.zerodayinitiative.com/about/

1 comments

Both of these organizations might be "helpful" if you have a new Internet Explorer vulnerability, but neither will likely help you with a CSRF bug in a bank website.
Still, thanks for sharing. Research ethics is always something I'm interested to read.