That's a strange way to disclose a security security issue.
That's a strange way to disclose a security security issue.
Reporting via a third party isn't super unusual if you think that a organisation may be a bit legal threat happy from your report.
I don’t mean to be trite, but publishing a bug bounty program doesn’t mean you’re the good guys.
this is meaningless rabble. Yes you can get burned in all kinds of legitimate situations [1], but 99.xx% of bug bounty interactions do not result in any kind of legal action even if you wander a bit out of scope
[1]: https://eu.desmoinesregister.com/story/news/crime-and-courts...
That is rich coming from yourself. Are you at all familiar with German law?
Then having journalists in the conversation helps, as they can produce bad press if the lawyers play games.
But in this case not. He must have been pretty worried about German lawyers and courts, which decided really strange lately.
Hard for me to take this particular outfit seriously after they decided to optimise for engagement by running to Entertainment Tonight.
I hope nobody is stupid enough to ever engage with this firm after this publicity stunt.
https://www.theregister.com/2024/01/19/germany_fine_security...
https://www.darkreading.com/vulnerabilities-threats/another-...