Hacker News new | past | comments | ask | show | jobs | submit login

We ought to recognize that others may not understand how to respond to security vulnerability reports. We can use this knowledge to be a little bit more wise in our own behavior.

The best approach may be if you are unsure as to what the response will be when you feel like you need to disclose a security vulnerability is to do so anonymously.




Definitely anonymously and with a hash of a secret message to prove it was you, in case there'll be a bonus.


If they don't understand responsible disclosure I doubt they will understand hashing.


And preferably on Reddit.


Or keep it to yourself and wreak havoc.


I'd suggest cheeky mischief over havoc.


Shenanigans.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: