Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

My opinion: security researchers attack an organization’s products, like their code or website or services. UMN attacked the organization’s people to test their defenses.

Lots of companies run bug bounty programs and thank you for finding vulnerabilities in their product. Humans don’t scale so well, though, and if you pester the hell out of a company’s office manager trying to social engineer them, that company is going to be super freaking annoyed at you.

If UMN had analyzed the Linux code to find problems, then patched them, the kernel team would be happy. They didn’t. They spammed the human maintainers with a flood of patches and lied about why they were sending them. They conducted an impromptu and unanticipated phishing test, and you just don’t do that.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: