Liegt bestimmt an der Firewall

Hanno's Blog

Tuesday, March 20. 2007

Liegt bestimmt an der Firewall


No Trackbacks

Display comments as (Linear | Threaded)

Didn't you say you practice responsible disclosure ?
#1 Matz on 2007-03-20 23:19 (Reply)
Well, first I wanted to note that I said I »usually« practice responsible disclosure.
Beside that, they have been informed before. So imho all requirements for responsible disclosure are met. It's not my fault if they're too stupid to understand the issue.
#1.1 Hanno (Homepage) on 2007-03-20 23:39 (Reply)
I think you can't expect the costumer support to know what a Cross Site Scripting Attack is. I think you should explain it to them and tell them to forward the message to someone who is responsible for the security.
#1.1.1 Matz on 2007-03-21 22:20 (Reply)
I'm a really a fan of responsible disclosure, but there are some borders. If someone proves to be too stupid to unterstand what the problem you can just publish it. I recommend Hanno to just blog after the first response. It is just not worth, spending more work on it. Just remember the story of Chris Shiflet and Amazon. He waited one year and nothing has been done on a really, really big hole.
You can insist, that one day is too less. I would be completely with you. Normally you should grant a much bigger period. But only if you can expect, someone will work on it. In the Napster case, you just can't.
#1.2 Lars Strojny (Homepage) on 2007-03-21 21:27 (Reply)
Die Email scheint wohl bei der Kundenberatung gelandet zu sein. ;-)
#2 Stefan Horning (Homepage) on 2007-03-21 16:57 (Reply)

Add Comment

E-Mail addresses will not be displayed and will only be used for E-Mail notifications.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.



This blog is written by Hanno Böck. Unless noted otherwise, its content is licensed as CC0.

You can find my web page with links to my work as a journalist here.

I am also publishing a newsletter about climate change and decarbonization technologies.

The blog uses the free software Serendipity and is hosted at

Hanno on Mastodon | Contact / Imprint | Privacy / Datenschutz