It's just a nice thing to do and they might reward you for it. You can still post it on your blog after they released a fix.
It's just a nice thing to do and they might reward you for it. You can still post it on your blog after they released a fix.
@rootlabs: Got the expected "not a bug" from @SlackHQ so
feel free to see names of MSFT, Google chats via login
info leak. http://t.co/kldKXN7NTf
https://twitter.com/rootlabs/status/499723782244675584I'd like people do be responsible when they discover a serious flaw in my programs, so I'll try to be responsible when discovering one in theirs.
Also Linus basically insults anyone for being alive.
Real people work at Slack, and very few of them were likely responsible for this oversight.
OP could still pat him/herself on the back after disclosing and waiting for a fix.
In this case the information seems unlikely to contain anything sensitive pertaining to customers. If it had though then the companies that had negligently put sensitive information on untrusted servers would be held liable and could face significant fines (violating the Data Protection Act 1998 in the UK can lead to fines of up to £500,000 and similar legislation exists in other parts of the EU). That more serious kind of breach is the one we are trying to avoid by advising companies not to use cloud services.
Note that elsewhere in this thread you can see that it was reported to Slack, but they responded saying it wasn't a bug.
How about next time you stop generalising?
You are under absolutely no obligation to do work for free that these companies should have been doing in the first place.