Hacker News new | ask | show | jobs
by firer 14 days ago
All too common... It's sad yet understandable how a company would not prioritize security.

At the same time, it's also understandable how a security start-up, upon (rightly) getting fed up waiting, decide to publicly disclose, as a way to scrape some PR out of the sunk cost. Public disclosure has a place. But if you truly care about helping, you could do more than bumping on HackerOne and messaging the CISO once on LinkedIn.

Maybe I'm too cynical but it truly feels like nobody actually cares at this point.

1 comments

This comment is so weird. It is so vague to me and feels so off, like an alien from Men in Black trying to pass as a human.

How do they not truly care about helping? Also what sunk cost? What does that mean?

Hah, not trying to pass off as human. Just communicating with my fellow men in black ;)

To be as explicit as possible: whether disclosing this publicly actually did more good then harm is not that clear cut. Even if accounting for all the second order effects.

Regardless, as a business you'd still be compelled to publish, because you've already poured resources into this research, there's still a chance to gain something, and there is enough plausible deniability about your true priorities.

We're in the worst of all worlds. Sometimes it feels like you only know it's a human because the AI would have over-explained.

But yeah, this security company only prodded, what, once or twice a month for 7 months? I mean, if they really truly cared, they would have found the CISO's home address, broken into their house, painted the reproduction steps on the inside of their front door (to avoid accidental disclosure), created a few "beginner friendly" repos with a git.exe that DDoS's their auth servers, got a job as a night cleaner in their offices, waited for one of the developers to leave their machine unlocked then fixed the vuln themselves.

It's just another capitalistic money grab, them posting their security concerns. Ugh.