3 ms·
Kinda nice that someone's going around showing how shitty the average company's security is. Not that I outright support crime, but it's good to have these anec
by staticassertion 4y ago
Kinda nice that someone's going around showing how shitty the average company's security is. Not that I outright support crime, but it's good to have these anecdotes to point to - silver lining, I suppose.
There's really only so much you can say about a company's security through a bug bounty. You can't show how devastating a vuln would be, you're stuck on the perimeter, etc. It leads to companies improving appsec a lot, which is great, but everything else is still weak.
- mkl95 4y agoYup. The average company lets their employees paste credentials on Slack, email them, etc. and they are allowed to be things like "password". The challenge is not really to hack them, is being willing to do it.
- guerrilla 4y ago> Kinda nice that someone's going around showing how shitty the average company's security is. Not that I outright support crime, but it's good to have these anecdotes to point to - silver lining, I suppose. Remember lulzsec? If not, I think you would have liked that drama.
- staticassertion 4y agoOh yeah, for sure. It seems like antisec has taken a significant back seat to bug bounties and the like.
- guerrilla 4y agoI wonder if that means they're actually paying enough or whether there's something else to it.