logoalt Hacker News

fossislifetoday at 9:10 AM1 replyview on HN

As a German I fear the only way I can see one of our government agencies to react upon an external pentesting report is if you threatened to release data from it anyway (this is not a recommendation, please don't raid my home). I just do not see them fixing even a dangerous bug if a stranger came along and told them to.


Replies

breisatoday at 10:16 AM

Thats far from reality. Just use the online form of BSI for disclosure. They contact the affected party for you. This way you optionally can stay anonymous and the vulnerabilities get fixed because BSI appears as the messenger.