Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm curious about responsible disclosure.

WhiteHat finds a security vulnerability. They tell the company. But, with banks, it's pretty hard to find the right person to tell. What steps should WhiteHat take to satisfy responsible disclosure? Just a printed letter to banks registered address is enough? (Banks, and everyone really, should have a "please use this address for responsible disclosure" - that would reassure me as a customer that they are taking security seriously).

But then, in England, we have a potential further step with the regulatory bodies. There's the ICO (information commissioner's office) who are overworked and will do nothing about this. And then there are the card companies who will, I'd have thought, be keen to protect their customers from fraud. Would responsible disclosure include a step to involve these third parties, if only to provide some clue pressure to the insecure site?



Sometimes the media can help. If you have a contact, they can put pressure on the company by calling them to interview about the vulnerability they are going to write a story on.

Back when I used to read the disclosure lists, I'd see people ask "I need a security contact as XYZ Inc." all the time.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: