Comment by SaucyWrong
7 hours ago
As a security software engineer I value and have a lot of experience with disclosures like this. At the last two B2Bs I worked at, I would also work personally with prospect security teams that wanted to run their red team at us (with approval and rules of engagement)
This is a valuable disclosure but I wonder about two things:
a) was the decision to run Strix against a prospective vendor domain negotiated in advance?
b) if the answer to a) is “no” then it is apparent that while Strix want to ensure their customers only run it against domains they own (totally fair) they have a double standard for their own use.
I don’t know, I’m accustomed to getting disclosures from any Jane or Joe via bug bounties etc., but it feels like a courtesy notice would be nice before a prospective customer lets their agentic hacker off the leash.
EDIT: for typos.
No comments yet
Contribute on Hacker News ↗