Should I tell the other party whether to be rewarded or punished for the discovered vulnerabilities?

Source: Internet
Author: User

Today I suddenly think of a question:

If a discovers a Password vulnerability that a company B provides to customers, such as a blog or album space, he can master the method of cracking, then, when a does not perform any destructive actions, he will take the initiative to tell B what kind of compensation should a get? What will you do if you find it? Audible color? Will it be a bit difficult? It's like seeing a neighbor's door unlocked?

Then, a netizen's answer surprised me very much: "around 2002, a traditional hacker discovered a company's vulnerability and did not do anything bad, in addition, a patch program was written to the company. (These actions must be observed by traditional hackers), but the company has taken the hacker to court. ."

Before a hacker discovers a vulnerability, he must use an unusual method to try it. I used several keys and several methods to find that the bank door can be opened under certain circumstances. I opened and closed the door. Then I did not disclose the method and took the initiative to notify the bank, have I broken the law? (In fact, I already think this is against the law, otherwise it will not be a mess, then it will be OK ?) I think there is still a little truth, but the software and hardware layers should not be confused. I think, from a legal perspective, it is more important to look at motivation. However, if you try to open the bank door, even if your motivation is to exercise the door-opening technology or purely fun, and you do not want to gain benefits from it, no one will believe this motivation.

Be careful when trying to discover or accidentally discover other people's vulnerabilities.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.