>Microsoft had editorial control over this post, cutting sections and figures and reshaping how the impact is described before publication.
that is... not great. shame on microsoft.
its actions like that which shed light on why we get the nighmare eclipses of the world. pressuring a kid into handing over full editorial control of a disclosure is gross.
Speaking of being sue, I once found a hole in a healthcare system. I solicited legal advice and the response was overwhelmingly against reporting. The company didn’t not have a bounty program. So I shut up knowing my info is sitting there exposed.
I wonder what’s the consensus on this? Do people normally report it or not?
On some forms I was advised to report hippa complaint. I can’t remember if I did. This was 10 or more years ago.
I think my take would be to report it anonymously (via support/marketing/etc.) and in the report strongly encourage them to create a path for security reports (either via a bounty or just a security email). When fixed or actually dismissed post publicly on anonymous channels, with a section saying how they could have created a channel for these reports.
john_strinlai · · focus · HN ↗
that is... not great. shame on microsoft.
its actions like that which shed light on why we get the nighmare eclipses of the world. pressuring a kid into handing over full editorial control of a disclosure is gross.
rkagerer · · focus · HN ↗
e.g. The $5000? Amnesty from being sued?
menomatter · · focus · HN ↗
On some forms I was advised to report hippa complaint. I can’t remember if I did. This was 10 or more years ago.
SahAssar · · focus · HN ↗