Posted in Linkedin spurns bug bounty hunter
Posted Tuesday 31st July 2007 19:46 GMT
Code of practice
It seems that there is room here for an industry agreed code of practice on both sides here. Clearly the vendor of any product that has a potentially disastrous bug in it has a duty to their customers to fix it. On the other hand any one who discovers the bug should not just blackmail the vendor, although in this case he did act ethically in as much as ,he offered the fix to the vendor first and not to the highest bidder whoever they were.
With out some kind of protocol to cover incidents like this, eventually there will be chaos.