Monday May 02, 2011

Report A Security Flaw, Get Sued

A researcher finds a security flaw in a company's software. He reports the flaw privately to the company...they threaten him with a lawsuit for extortion. And no, although it is the same tactics we read about last week, the company isn't Best Buy. big grin

"It came out of nowhere," Acidgen says of the legal threat. He was awaiting word on when the vendor would be issuing a patch: "Then I get back a really threatening lawsuit letter that they are going to press charges for extortion for [the] exploit code," says Acidgen, who says the PoC he gave Magix is a benign one that just starts up the Windows Calculator.

Comments