Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I found the password (actually, it used an s/key generator[0]) by similar means to this write up. It didn't matter if I "found" it again because at this point I was in direct contact with them and considered "trusted". The principle that someone else could just as easily find it gets back to the lighting striking twice argument, and was refuted for a long time. Eventually they agreed to change behavior but it took a while.

The timeline on the below link only refers to one specific incident, the time discussing this in principle went for roughly 11 months, and left me extremely disillusioned with the concept of responsible disclosure.

[0] https://github.com/technion/lhnskey



Really they have no idea how many times the "lightning" struck anyway. It was just once that they'd been told of.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: