Branding it as “responsible” puts the thumb on the scale that somehow not coordinating with the vendor is irresponsible.
Branding it as “responsible” puts the thumb on the scale that somehow not coordinating with the vendor is irresponsible.
Even the most security-aware companies have a process to fix vulnerabilities, which takes time.
I would never hire someone that doesn't reaponsibly coordinate with the vendor. In most cases it's either malicious or shows a complete lack of good judgement.
In the case of bobdajrhacker? Both.
But I find that this case is rare. Typically it would be something like many of the following being met:
- It is likely to be discovered by an attacker soon.
- History shows that the company is unlikely to fix it soon.
- Users have some way to protect themselves.
- Your disclosure is likely to reach a significant number of users.
It seems pretty reasonable to publish, given that?
"Day 1, same day: RBI fixes everything faster than you can say "code red""
So yes, anyone who discloses before the company has had a reasonable chance to fix things is indeed irresponsible.
Maybe things are better now.
Years ago the only contact for many companies was through customer service. "What do you mean you're in our computer? You're obviously on the phone!"
Doing the right thing can be awfully unpleasant.
Near the bottom of the blog post it says:
> When | What Happened
> Day 1, same day | RBI fixes everything faster than you can say "code red"
> Credit where it's due – RBI's response time was impressive.
I'm so sick and tired of some companies that any vulnerability I find in their products going forward is an immediate public disclosure. It's either that or no disclosure, and it would be irresponsible not to disclose it at all.
Cracked a thrift store IoT medical device. Contacted vendor. They sent me a one way NDA. Lol no.
The platform knows my identity, publishing the details would be against their terms, there's an implied threat that they could take legal action against me if I published the details, and they even low-balled the severity to avoid paying out the appropriate amount. Awesome experience overall.
I'm not suggesting in this thread that coordinating with vendors is bad. I'm suggesting that to frame any non-coordinated disclosure as inherently irresponsible is bad, and that is what is implied when we use the label "responsible disclosure" for "coordinated disclosure".
Thats not putting my thumb on the scale so much as shouting my opinion. The rebrand puts its thumb on the scale specifically because it avoids saying “we think non-coordinated disclose is irresponsible”; it sneaks it under the name change.