|
|
|
|
|
by zaroth
2529 days ago
|
|
I’ve never heard Full Disclosure concepts applied to serving stolen PII in an API. The reason is that the purpose of full disclosure is to shame the vendor into ensuring the patch is made, and to warn the user base that the attack is possible, while disclosing a flaw in a commercial product. In this case, we are not effectively doing either naming or shaming by publishing actual email addresses, rather than just user counts and the type of hashing that was performed. And at the same time the information being “bartered” is private user information and not merely identifying a flaw in a commercial product. I fail to see how an API into the HIBP database can be justified under the concept of full-disclosure. Particularly when the service could have been implemented as an email report to the queried email address. |
|
But once I put that down in writing I discovered you are right about the difference in this instance.
The person who has the right to know about the flaw in this instance is the list of people whose accounts were compromised. Giving it to the general public is to further victimize them, rather than help them protect themselves.