4 ms·
I agree, especially with risky parties like banks, or government institutions. It's always a scary experience. The funny thing is according to them I was the
by ic4l 6y ago
I agree, especially with risky parties like banks, or government institutions.
It's always a scary experience.
The funny thing is according to them I was the only contributor from 2016 to the end of 2017. So they must not get many reports.
Since then they did develop a disclosure program, but it would be great to hear from anyone else that reported things to them after the end of 2017.
- tyingq 6y ago"The funny thing is according to them I was the only contributor from 2016 to the end of 2017. So they must not get many reports." Probably because there's no obvious way to submit one.
- ic4l 6y agoThey had one a few months after https://responsibledisclosure.jpmorganchase.com/hc/en-us https://responsibledisclosure.jpmorganchase.com/hc/en-us
- Defenestresque 6y ago>All attack payload data must use professional language Huh.
- aidenn0 6y agoThey probably want to check PoC into their repository and banks take a very dim view on unprofessional language in the DB. I would only be slightly surprised had the terms included: "All code must be written while wearing professional attire"