Hacker News new | ask | show | jobs
by nhm 4777 days ago
I just wrote my own post about how, two weeks ago, I could log in to Yahoo Mail with any password (http://nick.malcolm.net.nz/2013-05-20-yahoo-imap-vulnerabili...).

I agree with Nils that talking to bots sucks! These are big issues, and it feels lame if you don't think the issue is being given the attention it deserves (even if that attention is directed at you).

1 comments

There's no problem putting it into a support ticket system - that's how issues get tracked and Alice going on holiday means things get followed up. But anything security related should be escalated immediately, skipping the typical CS levels. You can't afford to waste the (limited) time/effort of people who can a) help you and b) embarrass you very publicly, by making them fight scripted support responses and non-technical CS staff.

[edit]: grammar