6 ms·
>> people ranging from the usual security-asshole This pretty much illustrates the attitude of most of the bug bounties programs holders.
by viach 7y ago
>> people ranging from the usual security-asshole
This pretty much illustrates the attitude of most of the bug bounties programs holders.
- vardump 7y agoYeah, that'd really put me off reporting anything.
- M2Ys4U 7y agoIf you read a (dead, for some reason) comment by the author, he explains what that means: https://news.ycombinator.com/item?id=20147573 https://news.ycombinator.com/item?id=20147573
- vardump 7y agoPerhaps he should be more specific in the blog post instead. Removing phrases like "security-asshole" in the first place would also go a long way.
- jbk 7y ago> Removing phrases like "security-asshole" in the first place would also go a long way. I absolutely refuse to remove phrases like that. This is exactly what some of those people are and because they are security people does not allow them to behave less well than other people. And I find that I'm being quite polite by not shaming those people publicly.
- dwndwn 7y agohey, I work in a low-level security group under a larger generic security org - at a general level, there are too many security-assholes and they make our lives harder when interacting with developers as they think we're all like that. security-assholes are a huge problem
- dimtion 7y agoVLC have a past with "security-asshole" that could explains why JB seems tired with some members of the infosec community in general. From what I've read from the past controversies, each time a security issue arises in VLC the team is attacked by an angry mob of infosecs. This blog post closing remarks summarize the recurring issue well: https://www.beauzee.fr/2017/07/04/videolan-and-https/ https://www.beauzee.fr/2017/07/04/videolan-and-https/