Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> So you’d rather researchers reach out to black hats with this information instead?

That is pretty much what they did. Posting publicly about the vulnerability most certainly meant that every hacker in the world tried (and probably succeeded) at reproducing it, all before the company had enough time to act.



As far as I can tell, their tweet was just:

> someone from @a16z get in touch, now. its bad. security related.

https://x.com/xyz3va/status/1807330215955177937

If your email bounces, I think reaching out over social media is reasonable for a fast response.


So you’d rather this happen? That is the question I asked.

Because this is explicitly what happens when a company doesn’t have a good process for accepting and responding to exploits.

The onus should entirely be on the company to invite researchers to find and report exploits in a responsible way. They are the ones at risk of losing millions of dollars over an exploit.


They didn't post publicly about the vulnerability; they reached out via twitter to tell them that they had one, without giving any details about it whatsoever.


Telling everyone that there's a vulnerability is usually as bad as providing detailed steps. No one was looking, and now you've pointed them in the right direction.


> No one was looking

It's a16z, not Grandpappy's Model Railroad Museum Showcase ("Come see a photo of the tiniest steam wagon in Sheboygan!").


what do you want them to do? nothing? we've already established that they tried to make contact.


How about - go to the company's contact page, look at the email address there, and use that?


Lol what a reach




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: