The security researchers did not seem too concerned with the feedback they got from the community prior to releasing this CVE.
The security researchers did not seem too concerned with the feedback they got from the community prior to releasing this CVE.
Seriously though, security research is starting to drift into bizarro land, security contacts at companies are inundated with port-scans asking for bug bounties because there's an open port and now people are registering CVEs on expected and documented behavior.
[0] https://devblogs.microsoft.com/oldnewthing/author/oldnewthin...
Remember that these people are essentially trying to earn a living by finding vulnerabilities, so it's no surprise that they'll try to spin anything as one, regardless of any other considerations.
I've used the term "security vultures" before in reference to such things. It's unfortunate that a lot of companies misunderstand or obey their requests, and in the process useful features are destroyed and software becomes more user-hostile.
People who have no reputation tend to worry less about their reputation.
Yeah that's just not done. Dutch: kinderen die vragen worden overgeslagen (it rhymes nicely) - kids that ask will be skipped/passed. I.e., if you ask for a reward (or sweets, in a kids' case), you certainly won't get any.
If you reward people that report silly stuff and then ask for money, that would be bizarro land indeed.