ICEBlock handled my vulnerability report in the worst possible way
ICEBlock handled my vulnerability report in the worst possible way

ICEBlock handled my vulnerability report in the worst possible way

cross-posted from: https://programming.dev/post/37090037
Honestly, apart from the report being potentially wrong, the researcher seems pretty entitled as well. Like good intentions and all that, but he's given him a week to fix the issue, usual practice in responsible disclosure are 90 days. We're not talking about a company here, it's some single random dude providing the app.
This really sounds like some personal issue written down for public drama, while making himself ridiculous for not knowing his own shit properly.
Security researchers feel entitled to use any kind of practice that does not comply with the security best practice homonculus to barge into the affairs of others, anyone found in default MUST remedy the situation of discontinue operations immediately, the security researcher has graced the community with his works and now that a flaw has been found it MUST be remedied and the security researcher is to be rewarded and adulated for his diligence and high moral standing !
This is an Apache server version error it takes 5 minutes to fix.
So fucking what? He is not being paid in any kind, and anything he does on that project is volunteer work. If he was not able to do anything on that project due to regular work, vacation, personal issues, or the simple fact that he didn't want to?
If you don't pay for a service, you don't get to decide what people do, deal with it