Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Where did it say that they took a month to fix? The hacker just checked in 2 weeks later and it was fixed by that point.




According to the timeline it took more than a week just for Filevine to respond saying they would review and fix the vulnerability. It was 24 days after initial disclosure when he confirmed the fix was in place.

Given that the author describes the company as prompt, communicative and professional, I think it’s fair to assume there was more contact than the four events in the top of the article.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: