All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

Security Researcher Discovers Critical Data Vulnerability in Sports Insurer Portal, Faces Legal Threats Instead of Cooperation

By

toomuchtodo

3mo ago· 12 min readenInsight

Summary

A diving instructor and platform engineer discovers a critical security vulnerability in a sports insurer's portal during a dive trip, exposing personal data including minors' information. When attempting responsible disclosure, the organization responds with legal threats instead of fixing the issue. The article details the vulnerability discovery process, the ethical dilemma of responsible disclosure, and the concerning corporate response prioritizing legal defense over security remediation.

Key quotes

· 3 pulled
What I found was so trivial, so fundamentally broken, that I genuinely couldn't believe it
What happens when you responsibly disclose a critical vulnerability exposing personal data - including that of minors - and the organization responds with legal threats instead of a thank you?
I'm a diving instructor. I'm also a platform engineer who spends lots of his time thinking about and implementing infrastructure security. Sometimes those two worlds collide in unexpected ways
Snippet from the RSS feed
What happens when you responsibly disclose a critical vulnerability exposing personal data - including that of minors - and the organization responds with legal threats instead of a thank you?

You might also wanna read