Hacker News new | past | comments | ask | show | jobs | submit login

It's not like your two options were either wipe the box or take over their twitter account.

A responsible pen-tester would have reported the issue privately and disclosed it publicly at a later date.

Take a look here for a protocol to follow in future http://www.wiretrip.net/rfp/policy.html




Interesting. Link bookmarked for when it's not midnight, I'll definitely take a read through that. It'd be nice to have a guideline of sorts, I guess.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: