view the rest of the comments
the_dunk_tank
It's the dunk tank.
This is where you come to post big-brained hot takes by chuds, libs, or even fellow leftists, and tear them to itty-bitty pieces with precision dunkstrikes.
Rule 1: All posts must include links to the subject matter, and no identifying information should be redacted.
Rule 2: If your source is a reactionary website, please use archive.is instead of linking directly.
Rule 3: No sectarianism.
Rule 4: TERF/SWERFs Not Welcome
Rule 5: No ableism of any kind (that includes stuff like libt*rd)
Rule 6: Do not post fellow hexbears.
Rule 7: Do not individually target other instances' admins or moderators.
Rule 8: The subject of a post cannot be low hanging fruit, that is comments/posts made by a private person that have low amount of upvotes/likes/views. Comments/Posts made on other instances that are accessible from hexbear are an exception to this. Posts that do not meet this requirement can be posted to !shitreactionariessay@lemmygrad.ml
Rule 9: if you post ironic rage bait im going to make a personal visit to your house to make sure you never make this mistake again
Really aren't supposed to make exploits you discover public until after you have notified all the proper authorities and waited a specified amount of time to give the effected vendors time to get things patched if possible. Even in the US, just making this stuff public without following these best practices will get you visited by the FBI because they will be wondering if you are naive and need a talking to or you are some kind of agent of chaos wanting to see the world burn.
edit: to cover your ass and prevent companies from trying to pull this shit it's best to at the same time file a report with the CISA if in the US or the CAC if in China via their websites in addition to making a CVE report.
Ugggh. I hate it when companies pull that shit. Just wastes law enforcements time and tarnishes the companies reputation. It always backfires spectacularly but some of them still try it rather than saying "thank you" and maybe paying a bug bounty reward to encourage people to not just sell the information to a certain Israeli cyber-weapons firm. Apple used to be famous for doing this shit and even they eventually caved after realizing it was counter productive.
It's shitty. Hunting down bugs and exploits is a clear social good, but capitalists view it as a threat bc it's often expensive to mitigate the exploit, especially if it's hardware or firmware. Getting the cops involved in just dirty. The cops very likely don't have any sympathy for a random white-hat hacker trying to do a good thing, especially once they get in to a "threat to national security" attitude. I hope Naomi is okay. She's really vulnerable as an out lesbian and just being an outrageously stylish person. : p