4 ms·
Perhaps using a pepper should be a key principle for such use cases? - https://dropbox.tech/security/how-dropbox-securely-stores-your-passwords https://dropbox
by leftcenterright 4y ago
Perhaps using a pepper should be a key principle for such use cases?
- https://dropbox.tech/security/how-dropbox-securely-stores-your-passwords https://dropbox.tech/security/how-dropbox-securely-stores-yo...
- https://en.wikipedia.org/wiki/Pepper_(cryptography) https://en.wikipedia.org/wiki/Pepper_(cryptography)
Their payouts for reported bugs under bug bounty program have been very low, for a service used at the scale of Lastpass I believe this is just not ideal.
> Points – $5,000 per vulnerability
- https://bugcrowd.com/lastpass https://bugcrowd.com/lastpass
- KMnO4 4y ago$5000? I think it should be in at least the same order of magnitude what the black market would pay for a leak. Most people wouldn’t sell data for $40,000 if the bug bounty was $35,000. But that lastpass leak is worth many tens of thousands more than the $5000 (average payout of $450) offered.