4 ms·
> Meanwhile, for any target an independent researcher can lawfully assess, the researcher retains the ability to ignore the bounty program and publish straight
by CiPHPerCoder 7y ago
> Meanwhile, for any target an independent researcher can lawfully assess, the researcher retains the ability to ignore the bounty program and publish straight to Twitter.
I've had vuln disclosures go bad before and after the rise in popularity of bug bounty programs, so I'm probably qualified to chime in here.
Before HackerOne, the default for a company that didn't receive vuln reports well was to threaten you and/or your employer with lawsuits.
This happened to me with Bullhorn and Intuit, despite my investigation and reports being unrelated to my employment. They ultimately went no where, but I imagine the conversation I wasn't present for was, at best, awkward.
Last year, under one of my aliases, I found a vuln in Credit Karma, and the H1 triage staff declared it out of scope. So I posted it on Github/Twitter.
Instead of threatening to sue, CreditKarma asked me to pull the tweets/gists and walked back the H1 triage decision and ultimately awarded a bounty for my finding.
Thus, I don't buy the chilling effects narrative the article tries to sell. It actually made security research more normalized than it used to be.
Just my unsolicited $0.02
- tptacek 7y agoOf course, I go back to the 1990s with this stuff, and your experience matches mine, to the extent that I got lawsuit threats for doing research on programs I ran on my own machines. I find the idea that H1 is making it legally riskier to conduct research patently silly.
- CiPHPerCoder 7y ago> This happened to me with Bullhorn and Intuit, despite my investigation and reports being unrelated to my employment. I should probably have added, before that comma, "threatening my employer".