Report A Security Flaw, Get Sued
A researcher finds a security flaw in a company's software. He reports the flaw privately to the company...they threaten him with a lawsuit for extortion. And no, although it is the same tactics we read about last week, the company isn't Best Buy. ![]()
"It came out of nowhere," Acidgen says of the legal threat. He was awaiting word on when the vendor would be issuing a patch: "Then I get back a really threatening lawsuit letter that they are going to press charges for extortion for [the] exploit code," says Acidgen, who says the PoC he gave Magix is a benign one that just starts up the Windows Calculator.
