I always suspected there's a little bit of survivorship bias (? not sure of the best term here) going on. If you haven't suffered the hoards, or had someone you know suffer them, you're likely to think some combination of "it only happens when it's justified" and "no one will care about little old me"
I've witnessed it happen to a colleague early on in my career. He posted how trivial it was to cause an IoT device to reset because they had a reset password only protected by hashing an English word that they changed every update. There are multiple security lapses there, and he didn't even mention the really scary ones, this one was almost silly.
Turns out the parent company of the IoT device and his parent company were the same, and calls got made, his post misunderstood by management, and he got told to find a new job somewhere else.
Still makes my blood boil, and I'd name names, but neither company exists anymore. It did teach me to be _very_ careful what I post online, even when I'm anonymous.
To be fair, sometimes things happen, and it can be good (I think JP said something like that). something like "never interrupt your enemy when they are making a mistake" - if people demonstrate their shittiness, help them.
It would just be your friend that got an (admittedly mandatory) wake-up call - other employees would too. The best remedy is just a totally neutral post/tweet detailing what happened, with no judgement at all - 3rd parties will get angry on your behalf, and a lack of initial anger will only motivate that moreso.
Yeah, that sounds mostly really unlucky :(. I mean, anyone can understand that a company fires an employee that publicises a security weakness in a product instead of clearing it internally. However, when the employee doesn't understand that he is an "employee" of that company... Sounds like an unfortunate mistake.. you can be fired for those.
I've witnessed it happen to a colleague early on in my career. He posted how trivial it was to cause an IoT device to reset because they had a reset password only protected by hashing an English word that they changed every update. There are multiple security lapses there, and he didn't even mention the really scary ones, this one was almost silly.
Turns out the parent company of the IoT device and his parent company were the same, and calls got made, his post misunderstood by management, and he got told to find a new job somewhere else.
Still makes my blood boil, and I'd name names, but neither company exists anymore. It did teach me to be _very_ careful what I post online, even when I'm anonymous.