4 ms·
It is great that you have a page specifically for reporting security issues. For some companies I had to resort to reporting security issues to the main contact
by soult 15y ago
It is great that you have a page specifically for reporting security issues. For some companies I had to resort to reporting security issues to the main contact address where it landed at some first-level support guy's desk who had no idea what to do and in the end I gave up and the security hole stayed open.
One thing though: Your bounty of $500 is quite low. I bet this whole incident did/does a lot more damage than that. And to be honest, if I had the choice between $500 and trolling Mark Zuckerberg by posting his private photos album online, I would probably chose the latter option (sans the posting a howto on a forum part).
Disclaimer: I am not a security researcher, I don't even look for vulnerabilities. I just sometimes stumble upon bugs and get curious what other side-effects this bug might cause.
- mkjones 15y agoGlad you like it! $500 is actually just the base bounty - I've seen payouts for quite a bit more depending on how nasty the bug is. At least for me personally, it's not the posting of one person's private photos that is most frustrating - it's public posting of repro instructions so that script kiddies can exploit a bug. That just seems irresponsible.