|
|
|
Ask HN: Tips for Submitting a Responsible Disclosure
|
|
3 points
by kazz
1939 days ago
|
|
I stumbled across a pretty big security vulnerability in a restaurant's online ordering platform the other day, but the company that built the platform doesn't really have much in the way of a public presence (no social media, just a single phone number and generic email on their website), and it definitely doesn't have a dedicated security contact. I reached out to them at their generic support@ email and am still waiting to hear back, but that got me wondering if anyone has any good tips for submitting responsible disclosures? Especially tips for submitting disclosures to small companies that might not be used to receiving or dealing with them. |
|