Google Doesn’t Thank RSnake
After having read Jeremiah’s post about being thanked publically by Google for responsible disclosure I was a bit ticked. I’ve probably done more for Google security than almost anyone who has worked there by various means of disclosure over the years and do I get any credit for it? No! Well that’s just unacceptable and I will not stand for it.
So I had to take matters into my own hands. Take that, Google!
Okay, all kidding aside, I was a little amused at this obvious con artistry. I’m not quite so easily socially engineered. Just because I get my name in lights that doesn’t exactly make me feel like I’m safe. And I _KNOW_ other people have disclosed vulnerabilities in their stuff over the years. So only with the vague hope that I might get my name on some obscure page on some website that is subject to change at any time I can fail to alert consumers that they are at risk and hope instead that Google decides to move quickly. Sorry, consumers first, evil advertizing empires second.



October 10th, 2006 at 4:57 pm
Rsnake, FWIW.. I am pretty confident that you really dont need your RL handle to be floated around .. you already have a style and flair which transcends those guys on the list.. in fact, I”ll trust the info you cut more then then some of the guys on that list.. !!
October 10th, 2006 at 5:25 pm
Hahah… I just had to poke some fun at Jeremiah. It’s all in good humor. He even posted about it too: http://jeremiahgrossman.blogspot.com/2006/10/jeremiah-thanks-rsnake.html
Yah, my RL name isn’t exactly top secret and will probably be far less so after another project I’m working on goes live, but for now it’s fun not to have a real name. Then I can go by “the hacker formerly known as RSnake”
October 10th, 2006 at 5:47 pm
Dude, I was expecting you to have engineered some hilarious injection of your own name into Google’s page but no such luck. Anyway, I tell people about your XSS cheat sheat all the time.
October 10th, 2006 at 6:12 pm
Hahah, that’s why it was funny - that’s what you were expecting, but no! Like when I was expecting to see my name, you were expecting to see an XSS. We have both been let down now.
October 10th, 2006 at 7:43 pm
haha - nice post. I’d love to see “Google would like to thank Rsnake and Quadszilla for their contiuned efforts to improve our offerings”.
October 10th, 2006 at 7:48 pm
Hahah, you’re right, they owe us… But no, really!!
October 11th, 2006 at 10:26 am
http://images.google.de/images?q=-%28inurl%3A%22%3Fid%3D%22+filetype%3A%22+%22%29
check this out, internal server error, mailed google 24th of sep didnt even get a response. what do u think of this error?
cheers..
October 11th, 2006 at 11:11 am
I definitely think your name should be on there. Responsible disclosure for shoddy programming or security or otherwise should matter and shouldn’t be ignored. You’re as much a contributer to Google’s success as anyone else. We should petition to have our name on the site somewhere. If were slightly more crazy I’d be out at the Googleplex with a picket sign… or something.
October 13th, 2006 at 7:05 pm
RSnake, it was entertaining looking at your handmade thankyou
Apparently, Google thank them for a reason and that is Guanxi
October 14th, 2006 at 5:03 pm
Hahah… Indeed…