5 ms·
If this article is accurate, and the hacker did consider alternative ways to make more money, or legal ways, then this really puts the blame on Twitter. If thei
by ben174 6y ago
If this article is accurate, and the hacker did consider alternative ways to make more money, or legal ways, then this really puts the blame on Twitter. If their bug bounty wasn't absolutely ridiculously low ($7,700 for oauth account takeover), then they could have prevented this. Essentially they're putting the value of security for their entire user base as $7,700. This bounty should be in excess of $1 million easily.
- sfkdjf9j3j 6y agoWould a social engineering attack even qualify for the bounty program?
- abhorrence 6y agoTypically social engineering attacks are excluded. However given the large scale of this attack, there’s an argument to be made that there should be systems in place to limit the damage one rogue (or manipulated) employee can do.
- mrfox321 6y agoThat assumes that the bounty should approximate the expected payout from some lawsuit against twitter plus loss of future cash flow due to the vulnerability. If that value is still small, then there is no incentive to raise the price of the bounty.