Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I can definitely see the reasoning behind not wanting to encourage people to don their black ski mask and attempt to weasel their way into the building beneath the cloak of "security researcher." You are absolutely right, the police are not going to split hairs attempting to decipher the intentions of the individual and will act swiftly to neutralize the threat.

However, this case is different. While it was absolutely an attack on Google's infrastructure, it was discovered through a vulnerable external web service. Even though the control panel application is not a Google product, it stores user passwords in clear text as decoding it seems to be trivially simple. At the very least, Google should be responsible for picking third party vendors that store passwords using one-way hashes ;).

If you ask me, this should be one of those special cases!



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: