Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
CODE PROJECT For Those Who Code
  • Home
  • Articles
  • FAQ
Community
  1. Home
  2. The Lounge
  3. How to report a security hole

How to report a security hole

Scheduled Pinned Locked Moved The Lounge
csharpdatabasesecuritybusinesshelp
7 Posts 7 Posters 0 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • X Offline
    X Offline
    Xiangyang Liu
    wrote on last edited by
    #1

    Suppose you are taking over the development of one of your company's commercial websites. You found a big security hole in the existing version which is in production already and you fixed it in the code. How do you or should you tell the upper management about this? Assume the following: 1. The people responsible will be very angry at you. 2. One of them is your good friend. 3. Nobody has exploited the security hole yet. 4. Based on past experience, you won't be rewarded or recognized for reporting this. Thanks.

    My .NET Business Application Framework My Home Page

    A M C D B 6 Replies Last reply
    0
    • X Xiangyang Liu

      Suppose you are taking over the development of one of your company's commercial websites. You found a big security hole in the existing version which is in production already and you fixed it in the code. How do you or should you tell the upper management about this? Assume the following: 1. The people responsible will be very angry at you. 2. One of them is your good friend. 3. Nobody has exploited the security hole yet. 4. Based on past experience, you won't be rewarded or recognized for reporting this. Thanks.

      My .NET Business Application Framework My Home Page

      A Offline
      A Offline
      amclint
      wrote on last edited by
      #2

      Shouldn't matter...we've all had our share of programming mishaps, if he put the security hole there intentionally to use it later for devious means he should probably be mad but otherwise big deal. You found it and fixed it, less work for you than if someone had hacked in and created a nasty situation with many privacy notices going out.

      amclint There's no place like 127.0.0.1

      1 Reply Last reply
      0
      • X Xiangyang Liu

        Suppose you are taking over the development of one of your company's commercial websites. You found a big security hole in the existing version which is in production already and you fixed it in the code. How do you or should you tell the upper management about this? Assume the following: 1. The people responsible will be very angry at you. 2. One of them is your good friend. 3. Nobody has exploited the security hole yet. 4. Based on past experience, you won't be rewarded or recognized for reporting this. Thanks.

        My .NET Business Application Framework My Home Page

        M Offline
        M Offline
        MoustafaS
        wrote on last edited by
        #3

        A company that respects it's employees, will have employees that will respect it,though reporting will be your only option [In case you like this company :)] and about your friend, you may report this hole to the responsible team so, they will feel good at you, fix it, and have their way to tell the upper management.

        ------------------------------
        "About my religion : Islam ..."

        1 Reply Last reply
        0
        • X Xiangyang Liu

          Suppose you are taking over the development of one of your company's commercial websites. You found a big security hole in the existing version which is in production already and you fixed it in the code. How do you or should you tell the upper management about this? Assume the following: 1. The people responsible will be very angry at you. 2. One of them is your good friend. 3. Nobody has exploited the security hole yet. 4. Based on past experience, you won't be rewarded or recognized for reporting this. Thanks.

          My .NET Business Application Framework My Home Page

          C Offline
          C Offline
          Colin Angus Mackay
          wrote on last edited by
          #4

          Xiangyang Liu wrote:

          How do you or should you tell the upper management about this?

          Office politics - I've never figured it out.


          Upcoming events: * Glasgow: Geek Dinner (5th March) * Edinburgh: Web Security Conference Day for Windows Developers (12th April) My: Website | Blog | Photos

          1 Reply Last reply
          0
          • X Xiangyang Liu

            Suppose you are taking over the development of one of your company's commercial websites. You found a big security hole in the existing version which is in production already and you fixed it in the code. How do you or should you tell the upper management about this? Assume the following: 1. The people responsible will be very angry at you. 2. One of them is your good friend. 3. Nobody has exploited the security hole yet. 4. Based on past experience, you won't be rewarded or recognized for reporting this. Thanks.

            My .NET Business Application Framework My Home Page

            D Offline
            D Offline
            DaTxomin
            wrote on last edited by
            #5

            First, make triple-sure you are right about this. If the situation is ugly at your company, they will pound you to bits if you are wrong. Then take a look at your standards and the answer will be clear for you as to what to do. You should also consider moving to another company. If things are like this, you will eventually leave anyway. BTW: if one of those is a "good friend", bring it up with him/her first. Test that friendship carefully though.

            1 Reply Last reply
            0
            • X Xiangyang Liu

              Suppose you are taking over the development of one of your company's commercial websites. You found a big security hole in the existing version which is in production already and you fixed it in the code. How do you or should you tell the upper management about this? Assume the following: 1. The people responsible will be very angry at you. 2. One of them is your good friend. 3. Nobody has exploited the security hole yet. 4. Based on past experience, you won't be rewarded or recognized for reporting this. Thanks.

              My .NET Business Application Framework My Home Page

              B Offline
              B Offline
              Bradml
              wrote on last edited by
              #6

              If the company treats it's developers so poorly then maybe there is another way to bring the exploit to their attention....


              Brad Australian - Captain See Sharp on "Religion" any half intelligent person can come to the conclusion that pink unicorns do not exist.

              1 Reply Last reply
              0
              • X Xiangyang Liu

                Suppose you are taking over the development of one of your company's commercial websites. You found a big security hole in the existing version which is in production already and you fixed it in the code. How do you or should you tell the upper management about this? Assume the following: 1. The people responsible will be very angry at you. 2. One of them is your good friend. 3. Nobody has exploited the security hole yet. 4. Based on past experience, you won't be rewarded or recognized for reporting this. Thanks.

                My .NET Business Application Framework My Home Page

                M Offline
                M Offline
                Member 96
                wrote on last edited by
                #7

                Just tell the person who you should normally tell this kind of stuff to. You work for the company and just as you expect a paycheque they expect you to do your job. (and make sure you're right of course as others mentioned). There is no gray room in this issue.

                1 Reply Last reply
                0
                Reply
                • Reply as topic
                Log in to reply
                • Oldest to Newest
                • Newest to Oldest
                • Most Votes


                • Login

                • Don't have an account? Register

                • Login or register to search.
                • First post
                  Last post
                0
                • Categories
                • Recent
                • Tags
                • Popular
                • World
                • Users
                • Groups