Life Theatertechnology

Community Verdict

Based on 68 community votes, the most popular answer to “Do I Expose a Security Flaw That Risks Millions?” is “Report the flaw through public channels” — chosen by 51% of voters.

Do I Expose a Security Flaw That Risks Millions?

Category: technology • Theme: Protecting Public Safety vs Loyalty to Employer

I work as a junior developer for a company that runs a major online payments platform used by millions. Last week, while fixing a random bug, I accidentally discovered a critical security vulnerability that could allow anyone to steal user funds with just a few lines of code. I tested it only in our test environment, but I know it would work live. I immediately documented everything and reported it to my manager, expecting them to sound the alarm. But instead, my manager told me to "keep this between us" and not tell anyone else yet, because we have an acquisition deal in progress. If this leaks, the deal could collapse and many jobs—including mine—could be at risk. Ever since, I haven’t slept well. I know how much damage this could do to real people if someone else stumbles on this bug. But my boss seems more worried about the company’s reputation and the deal. If I report it through the platform’s public bug bounty or warning channels, it would guarantee that clients and regulators find out, and probably tank the acquisition. I know whistleblower protections exist in theory, but in practice I could easily be blacklisted or sued. On the other hand, if I stay silent and just hope our team patches it before someone malicious finds it, I keep my job and the company survives, but what if someone is hacked in the meantime? I feel trapped: do I go public and risk my career, or stay quiet and hope for the best? What would YOU do?

Vote Results — 68 Community Votes

Join the debate and cast your vote at Life Theater.

More technology dilemmas →