TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: To expose a security flaw or not? (at a company where I Interviewed)

5 点作者 ziggystardust超过 8 年前
tl;dr: hacked into potential employers web app, gained access to client details. can&#x27;t decide whether to tell them or keep quite. help!<p>I recently interviewed at a company for product engineer position. I got a decent offer from them, but for some personal reasons I could not accept it.<p>Before going in for the interview.. I did a little bit of research on their company and found a few security flaws in their web app through which I was able to get access to most of their client details as well. now, I&#x27;m confused whether to help them out with the issue or to keep it low considering there are chances of it backfiring on me (though I had a good time during the interview process and a healthy conversation with the people there)<p>what would you do?

3 条评论

mariuolo超过 8 年前
I don&#x27;t think you have anything to gain from telling them and potentially much to lose.<p>All it takes is an obtuse manager or a lawyer wanting to cover the company&#x27;s back (they could be required by law or by contract to disclose any successful penetration) or just a prosecutor eager for another notch on the belt.<p>Perhaps those are extreme cases but I wouldn&#x27;t take the chance if I were you.
new_hackers超过 8 年前
Let them know privately, then forget about it. (Forgetting about it includes deleting your copy of the client data.) You declined the offer, so its not your problem. However, as a good netizen, you can gain some good karma by letting them (and only them) know about it. Who knows, your good deed may open up opportunities down the road.
评论 #12544198 未加载
Lordarminius超过 8 年前
You may want to read this article <a href="https:&#x2F;&#x2F;techcrunch.com&#x2F;2016&#x2F;09&#x2F;20&#x2F;hacking-for-investor-profit&#x2F;" rel="nofollow">https:&#x2F;&#x2F;techcrunch.com&#x2F;2016&#x2F;09&#x2F;20&#x2F;hacking-for-investor-profi...</a>