• Zamboni_Driver@lemmy.ca
    link
    fedilink
    English
    arrow-up
    9
    arrow-down
    3
    ·
    2 days ago

    This doesn’t seem that bad to be honest. Disclosing they the access happened and what vulnerability allowed it to happen is a responsible course of action.

    • gian
      link
      fedilink
      English
      arrow-up
      4
      ·
      1 day ago

      Only if you have a written authorization from the company you try to attack.
      Else they are nothing better than a criminal hacker.

      • Zanacross@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 day ago

        I don’t feel like many white hat hackers get permission to exploit these vulnerabilities to report them

        • gian
          link
          fedilink
          English
          arrow-up
          3
          arrow-down
          1
          ·
          1 day ago

          They get permission when they do it professionally or as a company. Else it is a crime anyway.

    • Pyr@lemmy.ca
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      1 day ago

      The response isn’t terrible, but the fact that it happened in the first place is ridiculous. They don’t state anything about fixing the issue on their end so it doesn’t happen again. They also don’t apologize either or admit that they fucked up, they frame it almost as if they are doing them a favour and should be grateful.