Researcher reveals huge Mac password flaw to protest Apple bug bounty
venturebeat.com
venturebeat.com
This is starting to look really bad for the infosec "community." Without rehashing all the old arguments around disclosure, and the sorta-recent arguments around bug bounties, we're now at the point where this doesn't not look like extortion.
"That's an awfully nice operating system you've got there. It'd be a shame if someone were to disclose a security flaw without giving you ample opportunity to fix it."
They don't owe apple anything, and they are not causing the damage (apple's negligence did). If apple doesn't want to handle this in private, they will have to handle this in public. I don't see the problem. Coordinated disclosure is a courtesy, not a rule.
You have to convince the technically disinclined that know nothing about disclosure, but know plenty about people acting in ways that "ensure their job security."
https://www.helpnetsecurity.com/2018/11/07/virtualbox-guest-...
> Zelenyuk has responsibly disclosed to Oracle (via the SecuriTeam Secure Disclosure program) another VirtualBox vulnerability over a year ago, but apparently Oracle took a very long time to fix it and ultimately failed to credit Zelenyuk for the discovery.
---
https://news.ycombinator.com/item?id=16000550
archived: https://web.archive.org/web/20180202100849/https://medium.co...
I Got Paid $0 from the Uber Security Bug Bounty
---
https://techcrunch.com/2013/08/18/security-researcher-hacks-...
Security Researcher Hacks Mark Zuckerberg’s Wall To Prove His Exploit Works