this post was submitted on 06 Jul 2023
66 points (98.5% liked)
Cybersecurity
6383 readers
221 users here now
c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.
THE RULES
Instance Rules
- Be respectful. Everyone should feel welcome here.
- No bigotry - including racism, sexism, ableism, homophobia, transphobia, or xenophobia.
- No Ads / Spamming.
- No pornography.
Community Rules
- Idk, keep it semi-professional?
- Nothing illegal. We're all ethical here.
- Rules will be added/redefined as necessary.
If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.
Learn about hacking
Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub
Notable mention to !cybersecuritymemes@lemmy.world
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
OP is just quoting me there I think. If they aren't quoting me then they did try to contact the developer...
Typical reasonable disclosure is in terms months usually, not "nearly a week". OP is being irresponsible at best by posting this before giving time to the developers to see, and act on it.
I mean, a dialogue over months, maybe. Over a week of hearing nothing even saying they got your email and are looking into it is pretty bad on the part of the lemmy devs IMO. The "responsibility" part of responsible disclosure goes both ways. Also, this is incredibly low effort to find. This isn't even XSS really, it's just a complete lack of link filtering.
It absolutely does, it also means following up, not "They didn't reply in a week so instead of trying other ways to contact them, I'm just going to post about it". They didn't even try to open an issue because they "don't use github" all while coming here talking about how bad the vulnerability is.
It's poor (lack of) judgement on OP's part.