2 ms·
Perhaps. We could argue the semantics of it, but it feels within the spirit of the VRP. It directly impacts the secure and correct functioning of a (the!) core
by TomAnthony 9y ago
Perhaps. We could argue the semantics of it, but it feels within the spirit of the VRP. It directly impacts the secure and correct functioning of a (the!) core Google service.
The VRP page [0] talks about the "maximum impact" and this impacts users and advertisers, as well as businesses relying on organic Google traffic.
However, I take your point - I'm aware this is not a typical sort of issue for a bounty.
To reiterate - I am grateful to Google that they run the bounty programme and that they awarded a bounty for this. I've previously reported several issues (e.g. [1]) that have not been rewarded any bounty, which is the nature of the programme and absolutely fine.
[0] https://www.google.com/about/appsecurity/reward-program/ https://www.google.com/about/appsecurity/reward-program/
[1] http://www.tomanthony.co.uk/blog/confirm-google-users-email/ http://www.tomanthony.co.uk/blog/confirm-google-users-email/