Ask HN: How to disclose a phishing vulnerability

https://news.ycombinator.com/item?id=673813
by youngian • 17 years ago
5 7 17 years ago

I am hacking together a proof-of-concept of a phishing attack on the sites of some financial institutions (mostly to make a rhetorical point). Frankly, it's not rocket science. I imagine if the phishers wanted to, they could have developed this technique by now. But I haven't found any record of this particular type of attack being disclosed to the public.

So: am I obliged to treat this like a security vulnerability? Warn said institutions of the problem, give them a grace period to make changes, all that? Or should I just announce it publicly? Morally, what's the right thing to do? Legally, am I on any shaky ground one way or the other?

Oh, I should also mention that I have no expectation of this information actually convincing said institutions to change their ways. It's not like an open port on their server or something, and I am guessing they've sunk plenty of money into their system and aren't going to revamp it because of one windbag on the internet. Honestly, I'm concerned that if they give any response at all, it will be to threaten me with legal action or something if I don't keep it quiet.

Related Stories

Loading related stories...

Source preview

news.ycombinator.com