I am a lawyer and my field do cross this area which the events have transpired.
First, yes, everyone should acknowledge that this matter has been handled poorly by their corporate in-house and external lawyers. These should not have happened. The company should face consequences. I advise my data controller corporate clients to reach out to the reporter/whistleblower immediately and have the IT team collaborate, at the very least talk to the person to effectively replicate the exploit so it can be thoroughly fixed. There should even be procedures on how this should be handled. I understand from the article that this is not how it's so done.
However, I feel obligated to note some different aspects, all of which are absolutely not intended to condone how this company handled the situation. I want to re-iterate; they should have handled it better.
Things to note;
1. They might have already reached out to the data privacy board. The data privacy boards, especially in Europe are very involved in the reporting procedures and in my experience, their experts are very reluctant about public disclosures if the breach/data leak is caused by an exploit. They (sometimes rightfully) do not trust to the private sector's biased explanation that this vulnerabililty has been "fixed" and sometimes effectively prevent public disclosures about the event, allowing only the affected data subjects to be informed about the event. The potential danger of re-exploitation and protection of the public far outweighs the public's (that is persons who are not affected by this breach) right to be informed of such event. Affected persons should be notified. You might not have been aware that these happened. It is their legal obligation to notify the affected data subjects but it is not their legal obligation to notify the reporter that the notifications to the data subjects are made.
2. You did the right thing reaching out to the company and upon some radio silence, contacting the competent authority. But sadly, your duties as a citizen end there. You played your part and did all you could have done if not more. Contacting the company again was not really required. If you found yourself losing sleep, you could have re-contacted the authorities with a data subject request or a right to be informed request. They are legally obligated (under GDPR) to respond to you.
3. Sadly, your e-mail, especially the line below is actually a threat that is actionable under many EU juristictions;
I am offering a window of 30 days from today the 28th of April 2025 for [the organization] to mitigate or resolve the vulnerability before I consider any public disclosure.
You cannot disclose this to public. Even with good intentions. This might enable the exploit to actually be exploited by ill-faithed persons and would cause more damage. The company is responsible for this vulnerability and they should face counsequences for their actions or the lack thereof, but going public about an exploit is absolutely ill-advised, even if this is intended to coerce the company into action.
Nevertheless, I wanted to re-iterate that this is not intended to condone the company's behaviors in any way. You did the right thing warning them and the authorities but further action might have caused more damage. It is always best to attend to this situations with the guidance of a data privacy legal consultant.
Made me remember the quote by Reinhold Niebuhr: "Frantic orthodoxy is never rooted in faith but in doubt. It is when we are unsure that we are doubly sure."
Lawyer here. Just very quickly, (i) a CEO's blog post itself is not legally binding on the company by nature, but it is a reflection of a corporate decision (typically the Board of Directors)behind the post. An action of this nature can only be challenged in court by the shareholders or dissenting board members in certain cases. (ii) a legal patent holder has every right of disposal over the patent, including the act of revoking it. (iii)I did not look for precedents for this but if a different company would re-issue Tesla's designs on their own name and tried to sue Tesla (i.e. trolling), I have serious doubts concerning not only on whether such revoked patents can be re-issued in somebody elses name but also, assuming thats possible, any judge or court would award any penalties to the original patent author in such lawsuit.
the link seemed to work when I pasted it. I originally oasted the link you shared, but HN immediately pronounced it as [dead]. The below seems to be working for me. Sorry for the fuss.
Not only is that hacking, it is also witchcraft, which is punishable by being burnt on a stake. Not to mention the heresy calling for immediate excommunication, the hacker at hand here should be ashamed of him/herself for the ever terrible deed that (s)he had committed.
I guess they don't see themselves as the community sees an all round and productive IT company. They had and do still have an abundance of market penetration (considering the business world in Europe and Asia and so on). They couldn't (maybe didn't) kill the desktop by replacing it with surface. They really could have, and the whole business world may be on tablets today, but they didn't do it. (and please don't tell me that the business world are on tablets today, tablets are still accessories to laptop and desktop computers)
I understand if anybody says "hey! MS is not a company as you or others would prescribe to be and you don't get what surface is and what it is for!" Maybe that's true. But they had lots of chances of coming back as a competitive, innovative actor and they keep grounding their chances with products like Windows 8. Last month, may father, who is an author and do not get along well with any computer called me and said: "I just could not work with this Windows 8." To note, he barely learned to cope with the old fashioned windows interface. Loading a considerable amount of cognitive load to consumers upon whom your market penetration depends does not seem like good idea. It at least is not "innovation".
We will see what the concept will be like in 5 to 10 years or so, when the planned obsolescence time of the currently available MS running hardware (and software for that matter) comes. But to replace things like Word, Excel? Quite possible, but difficult. When those can be replaced, I think we will see whether the company stands over a house of cards or not.
Well, they should have contacted the developer of the interface beforehand. If that was not plausible, they should have given all the students a heads-up a suitable time before blocking.
If they had done all the above, then I don't know what the fuss is all about.
Same comment, I though I should also add this here:
One clearance, I don't say people do not comment. Maybe I did not write this clear enough. So let me:
Employees do comment. That is not the problem. What I am saying is why do we not see threads where employees actually discuss a product/procedure, and opine on how they can better that product/procedure. These are personal opinions and given this is not a blog and our identities are not out in the open (at least not immediately accessible), everybody can, while staying under the veil of HN, state their honest opinions. Much like anonymous surveys, but more detailed. Nobody has to disclose sensitive information, but opinions of employees do make a difference. I would like to see that on HN.
One clearance, I don't say people do not comment. Maybe I did not write this clear enough. So let me:
Employees do comment. That is not the problem. What I am saying is why do we not see threads where employees actually discuss a product/procedure, and opine on how they can better that product/procedure. These are personal opinions and given this is not a blog and our identities are not out in the open (at least not immediately accessible), everybody can, while staying under the veil of HN, state their honest opinions. Much like anonymous surveys, but more detailed. Nobody has to disclose sensitive information, but opinions of employees do make a difference. I would like to see that on HN.
First, yes, everyone should acknowledge that this matter has been handled poorly by their corporate in-house and external lawyers. These should not have happened. The company should face consequences. I advise my data controller corporate clients to reach out to the reporter/whistleblower immediately and have the IT team collaborate, at the very least talk to the person to effectively replicate the exploit so it can be thoroughly fixed. There should even be procedures on how this should be handled. I understand from the article that this is not how it's so done.
However, I feel obligated to note some different aspects, all of which are absolutely not intended to condone how this company handled the situation. I want to re-iterate; they should have handled it better.
Things to note;
1. They might have already reached out to the data privacy board. The data privacy boards, especially in Europe are very involved in the reporting procedures and in my experience, their experts are very reluctant about public disclosures if the breach/data leak is caused by an exploit. They (sometimes rightfully) do not trust to the private sector's biased explanation that this vulnerabililty has been "fixed" and sometimes effectively prevent public disclosures about the event, allowing only the affected data subjects to be informed about the event. The potential danger of re-exploitation and protection of the public far outweighs the public's (that is persons who are not affected by this breach) right to be informed of such event. Affected persons should be notified. You might not have been aware that these happened. It is their legal obligation to notify the affected data subjects but it is not their legal obligation to notify the reporter that the notifications to the data subjects are made.
2. You did the right thing reaching out to the company and upon some radio silence, contacting the competent authority. But sadly, your duties as a citizen end there. You played your part and did all you could have done if not more. Contacting the company again was not really required. If you found yourself losing sleep, you could have re-contacted the authorities with a data subject request or a right to be informed request. They are legally obligated (under GDPR) to respond to you.
3. Sadly, your e-mail, especially the line below is actually a threat that is actionable under many EU juristictions;
You cannot disclose this to public. Even with good intentions. This might enable the exploit to actually be exploited by ill-faithed persons and would cause more damage. The company is responsible for this vulnerability and they should face counsequences for their actions or the lack thereof, but going public about an exploit is absolutely ill-advised, even if this is intended to coerce the company into action.
Nevertheless, I wanted to re-iterate that this is not intended to condone the company's behaviors in any way. You did the right thing warning them and the authorities but further action might have caused more damage. It is always best to attend to this situations with the guidance of a data privacy legal consultant.