Ask HN: To expose a security flaw or not? (at a company where I Interviewed)
tl;dr: hacked into potential employers web app, gained access to client details. can't decide whether to tell them or keep quite. help!
I recently interviewed at a company for product engineer position. I got a decent offer from them, but for some personal reasons I could not accept it.
Before going in for the interview.. I did a little bit of research on their company and found a few security flaws in their web app through which I was able to get access to most of their client details as well. now, I'm confused whether to help them out with the issue or to keep it low considering there are chances of it backfiring on me (though I had a good time during the interview process and a healthy conversation with the people there)
what would you do?
8 comments
[ 4.6 ms ] story [ 22.9 ms ] threadIs there a way to leverage the client info if it's an anonymous tip?
All it takes is an obtuse manager or a lawyer wanting to cover the company's back (they could be required by law or by contract to disclose any successful penetration) or just a prosecutor eager for another notch on the belt.
Perhaps those are extreme cases but I wouldn't take the chance if I were you.