‹ BackHN Continuity

Thread

Hackers Got Inside a Flock Camera

586 points · 270 comments · driverdan

  1. vayup · · focus · HN ↗
    If you want to know what a "Vulnerability Disclosure Policy" (VDP) would look like if its main purpose is to claim we have VDP and create an appearance of responsible security posture, but not really to learn about vulnerabilities - read Flock's VDP.

    They sincerely welcome your vulnerability disclosures, except in cases where you have to "interact" with the device/service or download its data. Other than that TINY carveout, everything is okay.

    Oh, if the vuln about configuration and hardening "preferences" like SSL/TSL - Sorry, not interested.

    And also, infrastructure vulnerabilities like DNS config - no no, try harder.

    I know what you're thinking..ha ha...but we are good guys. You can still report vulnerabilities in the above categories, but the onus is on you to convince us that we should care about them. It is only fair.

    <a href="https:&#x2F;&#x2F;www.flocksafety.com&#x2F;legal&#x2F;vulnerability-disclosure-policy" rel="nofollow">https:&#x2F;&#x2F;www.flocksafety.com&#x2F;legal&#x2F;vulnerability-disclosure-p...

    1. scoutt · · focus · HN ↗
      &gt; Oh, if the vuln about configuration and hardening &quot;preferences&quot; like SSL&#x2F;TSL - Sorry, not interested.

      &gt; And also, infrastructure vulnerabilities like DNS config - no no, try harder.

      It&#x27;s understandable. If you have or manage a website you will receive daily emails (the kind that start with &#x27;Hello sir&#x27;) about automated scans finding low-hanging fruits like that, pretending a bounty payment.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.