I think MyBB did fine with the level of reporting they had with this story, and I CERTAINLY don't want anything that makes Google search less useful with the forums. Heaven knows it's the only way to find anything on here.
I also think that MagicDude4Eva is getting mighty sassy about the world of responsible disclosure,
when he's not shy of blabbing all over the forum after trying for less than 30 minutes to report responsibly. Maybe his views have just evolved significantly over the last three years.
Completely different issue:
Disclosure:
- COJ was informed about the issue already on the 13th August 2013 and did not respond. They also did not action it a week later.
- COJ was also informed about the issue by another person
- Furthermore, Google had information indexed for months before that
Vulnerability:
- It was an
OWASP A4 and required to be logged into COJ
- No security credentials were leaked. No data was leaked in bulk and no security credentials/passwords were ever accessed.
- People gained access to other people's invoices (comparable to going through someones postal mail) through their own logins. The exposure was minimal as people gaining access to data were known to COJ.
Mitigation
- COJ could have shut down the website immediately when informed but chose not to
- Although various people on MyBB bulk-downloaded COJ data no obvious damage was done to customers
- COJ should have logs of who accessed what information, so it is very easy to pursue people if they choose to
- Google indexed a large number of COJ data which remained in caches for weeks after MyBB went public and was in Google search several months prior to publication
TL;DR: The COJ incident was responsibly reported and COJ decided to not lift a finger for a good week (nor acknowledge the issue). I have always maintained that a security breach should be responsibly reported so that the affected parties can take ownership and mitigate. FWIW - I have insight into that investigation and what is happening, and you don't.
You have a very naive view in thinking that a vulnerability/breach becomes only "real" when it is reported. Many breaches are never reported to the public (ask anyone working for financial institutions or Sita) and are silently covered up. There have been several cases this year alone where JSE companies paid crypto-locker ransom as well as Btc to have pastes disappear. What do you think happened from 2013 when the C99Shell was installed on the server until now? Many attackers work and harvest data silently for months and years without the target ever knowing.