>Microsoft had editorial control over this post, cutting sections and figures and reshaping how the impact is described before publication.
that is... not great. shame on microsoft.
its actions like that which shed light on why we get the nighmare eclipses of the world. pressuring a kid into handing over full editorial control of a disclosure is gross.
Speaking of being sue, I once found a hole in a healthcare system. I solicited legal advice and the response was overwhelmingly against reporting. The company didn’t not have a bounty program. So I shut up knowing my info is sitting there exposed.
I wonder what’s the consensus on this? Do people normally report it or not?
On some forms I was advised to report hippa complaint. I can’t remember if I did. This was 10 or more years ago.
if you are reporting it for moral/ethical reasons, but are worried that the company will have a shitty response, report it anonymously to the company and any relevant regulatory bodies.
but most companies, even without a bounty program, are happy to receive reports. a lack of a bounty program isn't really an indicator of how they will treat reporters, as most companies are ill-equipped to have a proper bounty program.
otherwise, and i know this is an unpopular opinion here, but i'm a big advocate of just posting the exploit publicly when a company makes it hard/scary to report it to them.
My issue was knowing that reporting would allow them to possibly discover my identity. Discovering the vul in itself may instead be considered unauthorized access.
john_strinlai · · focus · HN ↗
that is... not great. shame on microsoft.
its actions like that which shed light on why we get the nighmare eclipses of the world. pressuring a kid into handing over full editorial control of a disclosure is gross.
rkagerer · · focus · HN ↗
e.g. The $5000? Amnesty from being sued?
menomatter · · focus · HN ↗
On some forms I was advised to report hippa complaint. I can’t remember if I did. This was 10 or more years ago.
john_strinlai · · focus · HN ↗
if you are reporting it for moral/ethical reasons, but are worried that the company will have a shitty response, report it anonymously to the company and any relevant regulatory bodies.
but most companies, even without a bounty program, are happy to receive reports. a lack of a bounty program isn't really an indicator of how they will treat reporters, as most companies are ill-equipped to have a proper bounty program.
otherwise, and i know this is an unpopular opinion here, but i'm a big advocate of just posting the exploit publicly when a company makes it hard/scary to report it to them.
menomatter · · focus · HN ↗