Settings

Theme

Ask HN: When to notify employer of security vulnerability?

2 points by x0ry 10 years ago · 4 comments · 1 min read


I stumbled upon a recent zero-day for Microsoft Silver Light (CVE-2016-0034 or KB3126036). Checking my work system, I can see it hasn't yet been patched. It's not my job to keep systems secure, I'm only a developer/analyst but ultimately I want to work my way into information systems security + do the right thing. What do you recommend is the best course of action? Do nothing? Wait? Report it immediately?

facorreia 10 years ago

It sounds as simple as sending an email to IT saying "it has come to my knowledge that there is this security vulnerability in the Silverlight version that we're using".

And then, probably, forget about it -- being too pushy about demanding an fast resolution may lose you the points that you'll gain by pointing out the issue.

justsorneguy 10 years ago

I would post to an online discussion, to obtain community feedback.

  • x0ryOP 10 years ago

    Are you saying like on an internal company blog or something?

shogun21 10 years ago

Report it immediately.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection