3 ms·
About two years ago, I spoke with Comcast's CISO over the phone about a leak of a sysadmin's home directory. It included private keys, log files, configs, licen
by bpchaps 8y ago
About two years ago, I spoke with Comcast's CISO over the phone about a leak of a sysadmin's home directory. It included private keys, log files, configs, licensed binaries, splunk(!), etc etc. A week before, her staff told me that they were going to use the chance to offer me a bug as part of a non-existent bug bounty, which didn't (and doesn't) exist.
She (paraphrased) told me that since it wasn't a "bug", it didn't deserve a bounty as part of a bug bounty program. She followed that dribble by saying that for them to implement a bug bounty program would be far too expensive because it would lead to them having to fix all of the security flaws at Comcast. No joke.
Dear Comcast: put out a fucking bug bounty!