Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I feel I should clarify, the writeup was not the blog but rather than vulnerability disclosure report (PDF) I sent to them directly.


To clarify the dates, the vulnerability was discovered on a Saturday (Friday evening) their time. It was reported on Tuesday (Monday their time)

The only email listed on their site was for the sales team which would not be checked on a weekend.


Yes, I understand, but that’s my point: In my experience, the detailed write-ups that external pentesters sent us could have been replaced by a 1-2 paragraph email for our engineers to read and fix ASAP.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: