12 ms·
no bounty and still politely reports it. Good guys need more praise.
by jbaczuk 4y ago
no bounty and still politely reports it. Good guys need more praise.
- baby 4y agoit's a public standard, who would pay such a bounty?
- mhh__ 4y agoSomeone who values security with real money
- morepork 4y agoI'm sorry, we lost millions of dollars due to an exploit. Don't you have bug bounties to find and fix these things? But this was in a public standard that we were using, we don't cover those. Do I look like I care?
- baby 4y agoAre you telling me this? Or are you going to pay a bounty?
- amenghra 4y agoA couple companies sponsor “the internet bug bounty”: https://www.hackerone.com/internet-bug-bounty https://www.hackerone.com/internet-bug-bounty IMHO, sha3 should be part of that bounty.
- deleted 4y ago[deleted]