Slashdot Mirror


Security-Closing The Holes While Gagged?

This, wisely anonymous, Anonymous Coward asks: "I am a paid participant of a survey, and as part of my participation I am not allowed to disclose my role in the survey to anyone. This is stated in the documentation though I haven't agreed to any NDA or contract that specifically says so. As part of the survey, users install client software, which I have found to contain a rather significant security hole. I have explained the hole in detail to the company doing the survey, though they haven't responded or updated the client software. I would like to expose the fault publicly to put pressure on them to fix it, though I fear that doing such would constitute a breach of confidentiality for which I would be liable, despite the lack of an NDA."

0 of 16 comments (clear)

No comments match the current filter.