3 ms·
I guess you have to trust that the company wouldn't go to the trouble of setting up a program (and making payouts) if it were going to treat vulnerability repor
by mkjones 15y ago
I guess you have to trust that the company wouldn't go to the trouble of setting up a program (and making payouts) if it were going to treat vulnerability reporters poorly. I think treating them poorly is generally a pretty bad long-term plan though, because of the negative light it casts the company in, the lack of future responses it will garner, and the hostility it may bring out (hello, Sony).
Do you feel like Facebook has ever "shit over" legitimate security researchers? I can see if I can help if you have examples.
- nl 15y agohttp://petewarden.typepad.com/searchbrowser/2010/04/how-i-got-sued-by-facebook.html http://petewarden.typepad.com/searchbrowser/2010/04/how-i-go...
- mkjones 15y agoI wasn't involved with that situation at all, but I don't think it involved any responsible disclosure of a security vulnerability.