hackwither_

notes / 12 June 2026

Acknowledgement is not remediation

when i was 16, i found a vulnerability that gave access to PII and financial data of ~399k government officers. i reported it to NCIIPC the way you're supposed to. i got the acknowledgment. the reference number. the polite email.
then i waited: one month, two months, nothing moved.

recently, a very similar story has been making headlines: different system, different researcher, same age range, same pattern. a vulnerability gets reported responsibly, acknowledgment arrives, and then little seems to happen until public attention forces action.

i'm not bringing this up again to say "i called it." i'm noticing a theme.

i don't think the lesson here is "researchers should go public faster." done the wrong way, it is unethical and most of us don't want to. going public is a last resort, not a strategy, and it should NOT be the only mechanism that makes remediation happen. that is not a sustainable model for securing critical infrastructure, imho.

sure, finding vulnerabilities is important, acknowledging reports is important. but neither of those things actually secures systems, remediation does.

and if the people repeatedly identifying weaknesses in critical systems are teenagers doing unpaid work in their spare time, then the question isn't whether young researchers are stepping up.
they CLEARLY are.

india has no shortage of talented researchers. the real challenge is ensuring that the systems, processes, and institutional remediation workflows around them can keep pace. im optimistic we can get there.

as always, happy hacking!!
–HackWitHer