<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: whatthefk</title><link>https://news.ycombinator.com/user?id=whatthefk</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 18 Apr 2026 09:27:27 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=whatthefk" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by whatthefk in "1 bug, $50k in bounties, a Zendesk backdoor"]]></title><description><![CDATA[
<p>1. "While this specific issue has been resolved", that was a bug, not an issue.<p>2. "they violated key ethical principles by directly contacting third parties about their report prior to remediation", what is a violation of ethical principles is to know about a security failure in your application and ignore it, leaving customers at risk, can't wait for some law to pass so people who behave like that face consequences.<p>3. "We have no evidence that this vulnerability was exploited by a bad actor.", tldr, it don't fixed it until some vendor dropped us, because before that happened, it was cheaper to ignore it.</p>
]]></description><pubDate>Sat, 12 Oct 2024 21:54:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=41823033</link><dc:creator>whatthefk</dc:creator><comments>https://news.ycombinator.com/item?id=41823033</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41823033</guid></item></channel></rss>