Quote:
Originally Posted by mrkris
I would like to actually answer this one. If fris would not have done what he had done, Brad wouldn't have known(?) about the issue, thus, if a blackhat found the hole, they could be stealing all of everyones information. Granted, fris might not have respected privacy by posting the info, but he got Brads attention and I am hoping by this point the issue is being resolved with the software. I myself am into pen-testing (just now getting into web-pen-testing) but the same concept applies. Someone has to do it to stay on top of the game, otherwise people will get owned.
|
I see what you're saying and where you guys are coming from, but it still doesn't answer my question.
Is fris in the habit of just picking a company and doing consulting work for them without actually being asked to or officially hired?
Is this some kind of good samaritan thing some of you guys are doing?
Unpaid exposing of exploits R us?
