4 ms·
So what did you learn out of this, and what would you do differently? What do you think people should do differently when reporting these issues?
by volta83 5y ago
So what did you learn out of this, and what would you do differently?
What do you think people should do differently when reporting these issues?
- paulryanrogers 5y agoThese questions imply the onus is on reporters of problems. I get the impression the root causes reside with the companies offering half hearted big bounties.
- paulryanrogers 5y ago^half hearted bug bounties
- volta83 5y ago> These questions imply the onus is on reporters of problems. Sorry, I did not mean to imply that and disagree with that statement. The problems are what they are. Fixing them is not the job of whoever encounters a security vulnerability. Yet if you encounter one, you still have to decide what to do. I encountered one in an Apple service a couple of years ago. Reported it. Never heard back. Vulnerability was still there 6 months afterwards, but I have better things to do than chase them. The action I took was simply to stop using Apple's products. But that was probably the wrong decision in hinsight, since the alternatives aren't really better.
- marcosdumay 5y ago> So what did you learn out of this, and what would you do differently? The obvious lesson is "don't participate in bug hunting programs".
- handrous 5y ago> What do you think people should do differently when reporting these issues? ... sell vulns to bad actors for Monero or something?