Ranter
Join devRant
Do all the things like
++ or -- rants, post your own rants, comment on others' rants and build your customized dev avatar
Sign Up
Pipeless API
From the creators of devRant, Pipeless lets you power real-time personalized recommendations and activity feeds using a simple API
Learn More
Comments
-
Don't go to the company - go to the press. Research and report anonymously and do proper SecOps.
-
Just make sure to report the company to their insurence provider. Make sure the company knows that you did.
The company will lose coverage, if anything happens. -
Actually there's a great marketplace out there where various 3 letter agencies will buy this kind of exploits for a decent price.
-
There may be some NGOs that can do the communication on your behalf. They avoid rookie mistakes and also keep you anonymous.
In germany for example, you can ask the ccc to do it. -
@ze3ter As i said: do proper SecOps. they can't arret you, if they don't know who found the bug and leaked it to the press.
Cyber sec team: If someone exploit it we'll fucking arrest you
joke/meme