5 ms·
I discovered this flaw 3 years ago and sent it to many bug bounty programs. Almost all were closed as informative/not a security issue and I was paid $50 for o
by hker999 4y ago
I discovered this flaw 3 years ago and sent it to many bug bounty programs. Almost all were closed as informative/not a security issue and I was paid $50 for one after 6 months as a low priority.
This issue will most likely never get fixed as I already let most of the companies in this article know it was a problem...and they just don't care.
- donclark 4y agoThis reminds me of credit card fraud and how companies (like VISA) dont seem to care either. As long as they are not held liable for the losses (or it does not cause a drop in users) why would they? Is there a class-action lawsuit possibility in both cases?
- quesomaster9000 4y agoIT security is an insurance problem, and the insurers may stipulate you need a pentest, which makes it not their problem and not your problem - just keep paying those premiums and the liability gets passed to the end-user ;) There is no class-action lawsuit, that's just business...
- Gigachad 4y agoIt’s the same in any industry. Try telling the local council they should build a road overpass over a pedestrian crossing because it’s safer and a few people have been hurt there. What you are saying is true, but it’s unlikely anything will be done because it’s expensive and not a huge risk.
- refurb 4y agoWhat would be your class action lawsuit for credit card fraud? Who are the plaintiffs?
- guessmyname 4y agoIt’s because one of the researchers works at Microsoft. I will assume they have contact who work at all the aformentioned companies, contact that allow the security report to escalate to the appropriate channels. I have reported the same security problems too in the past to several companies, and the majority of them have been closed as “informative/non-actionable” too.
- albert_e 4y agoThe article states > Fortunately, all the affected services were notified of the vulnerabilities and have implemented the necessary fixes. this is right after they list the affected services > Top services affected > In their study, the researchers examined 75 services that ranked among Alexa’s list of top-150 high-traffic domains. At least 35 were affected by one or more account pre-hijacking attacks, including Dropbox, Instagram, LinkedIn, WordPress.com, and Zoom. Fortunately, all the affected services were notified of the vulnerabilities and have implemented the necessary fixes.
- hker999 4y agoMost likely because of the perceived bad press.