4 ms·
Refusing to interact with an existing security process (HackerOne) and demanding a personal contact instead for a minor issue is certainly an interesting take.
by cr3ative 4y ago
Refusing to interact with an existing security process (HackerOne) and demanding a personal contact instead for a minor issue is certainly an interesting take.
- denton-scratch 4y ago"Hey neighbour, you left your front-door open". "Can you notify my lawyer by FAX, please? And can you get the document notarized first? Kthxbai".
- mdbug 4y agoYou find "interesting" that someone just wants to report a security vulnerability without having to accept any conditions first? Funny, I find it interesting that they want to pay a bugbounty even though nobody asked for it. But I guess paying hush money is just cheaper than having to seriously fix the issue.
- malaya_zemlya 4y ago>But I guess paying hush money is just cheaper than having to seriously fix the issue. They did fix the issue, though.
- Anunayj 4y agoThey just marked something the way exploit was done as "malacious", without fixing the root problem, or informing the the reporter that they "fixed" it. Instead claiming it was never there. That is very unprofessional! And if these guys were to go though the NDA route, The company may choose just not to fix it at all, and tell these researchers to be quiet about it. And you'd never know there was such a exploit ever.
- CoastalCoder 4y agoI don't get the impression that the researchers were simply being lazy or attention-seeking. They objected to having to sign an NDA, when there was no clear incentive to legally bind themselves in that manner.
- rroot 4y agoIt's interesting that they don't want to sign an NDA when there's absolutely nothing in it for them. Utterly astonishing. I'm hopping mad.
- xbar 4y agoThis is a case where an email from mod zero to security@crowdstrike.com should have been enough to get the SOC to read and route the vuln to the product team and get a fix implemented. NDA? HackerOne? Personal Information with Identity and Credit History Verification, Cookies and Disclosure Agreements, and 3rd party terms? Why is it at all "interesting" that a security researcher is not interested in giving all of up in order to tell CrowdStrike that their core product is broken in a way that is completely inimical to its mission purpose?
- tptacek 4y agoThere's nothing at all weird about refusing to work through HackerOne. If you're not violating contracts (or the law) to conduct the research in the first place, you're not required to work through a bounty program at all; you can just disclose directly. Part of the point of a bounty program is to limit and control how disclosure happens; if your priority is the disclosure and not the cash reward, you won't want anything to do with H1.