Skip to content

Comment on What to do when a company refuses to fix a vulnerability I disclosed to them?

Comments

Couldn't this vulnerability simply be published without mentioning who is directly affected? E.g. "under x and y circumstances, it is possible to do z and everyone is advised to check and correct this".

If this is not an option it means it is something very specific of that company, and what would be the purpose on releasing the vulnerability to the public?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.