3 ms·
Just that they have a name that will immediately be without any trust at any non -tech company. Basically mentioning "hacking" will make any non-technical CEO s
by summarite 9y ago
Just that they have a name that will immediately be without any trust at any non -tech company. Basically mentioning "hacking" will make any non-technical CEO shiver and call the lawyers.
- anigbrowl 9y agoOK, let the lawyers handle it. You don't make progress by catering to other people's ignorance and insecurities.
- mcmarables 9y agoYou are right, that isn't how you make progress: it's how you make money.
- sytse 9y agoThe name is not ideal. I've heard a story of it also not being great for employees when talking to custom officers :/ But any person looking at their homepage would be a lot less concerned. Impressive logo's and a clear story for an enterprise audience.
- tptacek 9y agoIt is unlikely that there is a company in the US that has a security team that hasn't heard of H1. They're kind of a big deal. Since they're the ones handling the first contact in these situations, you can safely let their name be their problem; they know how to explain themselves. The more realistic concern here is that for these kinds of findings --- CSRFs in random web applications --- there simply isn't going to be a contact at the target company, and H1 isn't going to find one for you. That's why they point out they can't promise a contact.
- yeukhon 9y ago>It is unlikely that there is a company in the US that has a security team that hasn't heard of H1. You'd be surprised. HackerOne is relatively new, just several years old. Does everyone know OWASP, almost certainly yes. Does everyone know the BSide community? No. Anyway, H1 can act as a shield, in this case. On the other hand, companies like WhiteHat or Rapid7 are probably more well-known since they will probably spam your security team on a regular basis trying to sell their products.
- dankohn1 9y agoDisagree. Any big company can be sufficiently ignorant, but Hackerone and Marten Mickos both have a brand name associated with them, partially due to their funding: https://www.crunchbase.com/organization/hackerone#/entity https://www.crunchbase.com/organization/hackerone#/entity I think the disclosure assistance is a pretty clever idea for generating new sales leads, since by definition they will be talking to companies with an actual zero day situation.