• passepartout@feddit.org
    link
    fedilink
    arrow-up
    83
    ·
    11 hours ago

    My friend who helped me research the OAuth vulnerabilities was let go for “security concerns from corporate”

    Good old shooting the messenger.

    • ZoteTheMighty@lemmy.zip
      link
      fedilink
      arrow-up
      11
      ·
      8 hours ago

      I mean, they were an employee who was exploring security vulnerabilities with a non-employee who has a blog. I would have fired them too.

      • passepartout@feddit.org
        link
        fedilink
        arrow-up
        7
        ·
        8 hours ago

        It is indeed a very risky move without a lot to gain for him personally. But I could guess McDonald’s would have forced him to ignore it and shut up about it if he disclosed this to the higher ups himself, in which case I would have gladly left myself instead.