4 ms·
How much did Element pay the researcher for this find ? Element has a bug bounty program, no ?
by Reventlov 4y ago
How much did Element pay the researcher for this find ? Element has a bug bounty program, no ?
- jeroenhd 4y agoI don't see a reference to this issue on their bug bounty page (https://app.intigriti.com/programs/matrix/matrix/detail https://app.intigriti.com/programs/matrix/matrix/detail) but it's possible that the researcher came to them directly or didn't want a reward. You'll have to ask the person who demonstrated the vulnerability. According to their responsible disclosure page (https://matrix.org/security-disclosure-policy/ https://matrix.org/security-disclosure-policy/) they don't generally do bug bounties. I'm not sure what their intigrity page is all about, perhaps they did in the past?
- vrfvr 4y agoResearcher? A click on the url to his homepage reveals that he is a backend software engineer who does volunteer work on free software and open protocols
- lucideer 4y agoWhat do you think a researcher is in this context?
- deleted 4y ago[deleted]
- AyyWS 4y agoNeeds a white lab coat.
- vrfvr 4y agoA person who's job it is to do research on security of software
- lucideer 4y agoSo pay is a prerequisite and not skillset? Surely that would just be a "professional researcher", no? And even so, does a freelance researcher "have a job", in the traditional sense?
- cjbprime 4y agoIn the infosec community, "researcher" is the noun of choice to describe anyone who has discovered a security vulnerability, no matter their motivation or experience.
- stjohnswarts 4y agoGotta be a PhD computer scientist in security at MIT else you're a poseur I guess? :)
- deleted 4y ago[deleted]
- Arathorn 4y agoElement currently piggybacks on the Matrix.org Foundation bug bounty programmes (which are the relevant ones here anyway, given matrix-appservice-irc is a Matrix.org project - i.e. owned by and managed by the Foundation, albeit with lots of contributions from Element employees) Right now the Matrix.org Foundation is between bug bounties - we ran an EU funded one via Intigriti last year (https://portswigger.net/daily-swig/intigriti-launches-eu-backed-bug-bounty-program-for-matrix-secure-communications-tool https://portswigger.net/daily-swig/intigriti-launches-eu-bac...) until the funding was consumed, and I'm literally about to sign the contract on a new permanent one for the Matrix Foundation funded by Element run by YesWeHack. EDIT: https://matrix.org/security-disclosure-policy/ https://matrix.org/security-disclosure-policy/ will get updated when the new bounty programme is live. You can see the history of that page over at https://github.com/matrix-org/matrix.org/commits/master/gatsby/src/pages/security-disclosure-policy.js https://github.com/matrix-org/matrix.org/commits/master/gats... in terms of when bounties have come & gone over the years.
- Reventlov 4y agoOk, thanks for the info (so, 0$).