Ask HN: I've reversed-engineered a private API, now what?
I was able to reverse-engineer a secure HTTP API of a website with over 10 million users to enable access from third-party clients (one has to authenticate with their login and password). This hack allows you to access you own data on the website, that's it, there is no malicious intent.
I have several options here:
* publish it on a popular blog and wait for the company to act on this (they probably won't be too happy) * report the vulnerability to the company, and when the fix it, publish the information
I really want to publish this hack, as it could be useful for others to learn how to reverse engineer APIs, and I also believe there is no reason why said API should be private in the first place, they should open it.
What would you do?