Hacker News new | ask | show | jobs
by buraksarica 2337 days ago
The OS level actions won't be fast. So this disclosure is closer to an irresponsible attitude. At least CAs should be informed.
1 comments

I tend to differ:

Netgear security is paid to manage security. They failed by not responding to these legitimate communications requests.

The researcher are not paid. They did what could be done to really fix the problem. Of course you can always do better as a researcher, always, but consider time available and paid vs. pro bono time. Also consider all the people who probably found this before and may have sold it on black market, you’re attacking the wrong people.