TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: How long to give a website to fix their security flaw?

3 点作者 lmai超过 14 年前
How long should one give for a website to fix their security flow before warning their customers? Corollary: How should it be done since I can't reach out to their customers?<p>Background: The hack is simply changing the id variable in the url. It's a serious bug as you can view some of my photos from my various social networks. This could be detrimental to the VC backed company as they just did a Groupon-type deal (which is how I came to be a customer).

1 comment

maushu超过 14 年前
Send a high priority email to their customer support (or alike), wait 24 hours, if no response is received then tell the customers (blog post? forum thread? hnews/reddit?).<p>If response is received wait a week or so and, again, check for the existence of the exploit.
评论 #1820462 未加载