TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: When to notify employer of security vulnerability?

2 点作者 x0ry超过 9 年前
I stumbled upon a recent zero-day for Microsoft Silver Light (CVE-2016-0034 or KB3126036). Checking my work system, I can see it hasn't yet been patched. It's not my job to keep systems secure, I'm only a developer/analyst but ultimately I want to work my way into information systems security + do the right thing. What do you recommend is the best course of action? Do nothing? Wait? Report it immediately?

3 条评论

facorreia超过 9 年前
It sounds as simple as sending an email to IT saying &quot;it has come to my knowledge that there is this security vulnerability in the Silverlight version that we&#x27;re using&quot;.<p>And then, probably, forget about it -- being too pushy about demanding an fast resolution may lose you the points that you&#x27;ll gain by pointing out the issue.
justsorneguy超过 9 年前
I would post to an online discussion, to obtain community feedback.
评论 #10912293 未加载
shogun21超过 9 年前
Report it immediately.