|
|
|
|
|
by _bxg1
2861 days ago
|
|
"I could have told Google directly about the problem, but then I'd have no cool story to publish on my blog" First of all, you definitely would. Standard practice is 1) report the bug privately, 2) wait for a fix, 3) get the go-ahead to publish your report and take credit publicly. That's how it always works; that's how security researchers build their reputations and careers. I guess you just weren't aware of that. Second of all, even if you wouldn't get to publish it, that is horribly selfish reasoning. Putting millions of people at risk of having their information stolen for the sake of a popular blog post? |
|
In this case, Google put millions of people at risk, and dejanseo actually contributed saving them.