Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Who's going to go after them? Heck, they may get an award for this.


If random security researcher does this kind of disclosure, fine.

But if serious company that seems to offer services to seemingly plenty of serious customers acts this way, I'd not want to be their customer, if they seem to have such a cavalier attitude, disclosing stuff without even a sniff of "we notified the company about the breach".


It was fixed. Disclosing it after it's fixed is responsible.


Uh, I don't know, but cannot DeepSeek do that, for starters? Being located in a different country than the service you are attacking doesn't really make you immune to being sued.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: