I would be very concerned about this backfiring, but, I would hack Rails a little to report when anybody attempts to use this glitch and wire that into Hubot(TM), so if he does attempt to use this same hole again, the devs are warned instantly
I would be very concerned about this backfiring, but, I would hack Rails a little to report when anybody attempts to use this glitch and wire that into Hubot(TM), so if he does attempt to use this same hole again, the devs are warned instantly
By pushing him out you create moral hazard for future users who discover vulnerabilities. You also, in the near term, risk pissing off the guy who found the vulnerability which could result in very real blowback.
I'm basing this on the assumption that he didn't do anything malicious, i.e. outside his own account. If he did then his near-term risk profile changes dramatically and the move would have been rational.
Given a hacker who found a vulnerability, exploited it within his account, and publicised it we can conclude that (1) he is smart (or lucky), (2) he does not pose an immediate malicious threat, and (3) he has the potential to become a serious problem.
Engaging with him carries the benefit of understanding the vulnerability while opening a dialogue that mitigates the hacker mutating into a serious problem. It carries the cost of not being able to claim, as GH did, that it pro-actively identified the vulnerability and thus looking weak. It carries the risk of giving the hacker time to rummage through more of the system.
Suspending him carries the benefit of being able to look strong while mitigating the risk of the hacker causing further damage. It carries the cost of losing a lot of emotional lee-way and thus future conversational runway with the hacker. It thus increases the risk of him turning into a serious problem in the shadows. There is also the risk that future users who happen upon vulnerabilities will think twice about publishing their finding under their real name.
Given, as many here have pointed out, that he can create a new account and be equally damaging (the risk is a property of him, not his account), the suspension offers no tangible benefit long-run benefit above that of managing perceptions. I don't know how sensitive GH's user base is to the perception of security.
The unknown here is whether GH has evidence that he acted maliciously, i.e. modified repos in accounts whose owners didn't give him permission to modify.
Working with him to do what? He pissed about a little with WebInspector, it doesn't make him a security consultant
He threatened to do more damage to your site, why wouldn't you suspend someone like that?