3 ms·
Interesting - I guess I didn't get "significant" spam either, but after a dozen or so beg bounties I had enough of it and removed it again. And now it's back to
by Aulig 3y ago
Interesting - I guess I didn't get "significant" spam either, but after a dozen or so beg bounties I had enough of it and removed it again. And now it's back to roughly zero beg bounties. Serious security researchers won't have a hard time clicking "Contact" in my website header & sending an e-mail to that address anyways.
- abirch 3y agoOnce this goes mainstream I'm betting on massive spam. I'd only list the contact us url
- bombcar 3y agoBeg bounties are getting more and more common.
- hsbauauvhabzb 3y agoWhat’s the best way to get things read? Prefix them with ‘I am NOT looking for payment, reward or bounty’?
- bombcar 3y agoHonestly, I at least glance at the beg bounties, but they're all so formulaic and bullshit it's easy to see what's up. Once I was getting too many to glance at, hard to say. Probably mailing a physical letter to the address of record (if it's not a company and so has no address, not sure).
- galleywest200 3y agoPutting that at the front of your email makes it sound even more sketchy to me.
- masklinn 3y agoJust report the issue honestly, don’t try to obfuscate, and don’t send a message to a security@ with something like “I found a security issue” with no details of any kind. If it’s not a security@ and not specifically listed as a security point of contact it’s fair to ask if it’s the right location for a potentially security-sensitive issue and whether there’s a better one.