7 ms·
> a16z did not give me any bug bounty on this because of the fact i publicly reached out instead of trying to reach out privately. the only reason i did it this
by Drakim 2y ago
> a16z did not give me any bug bounty on this because of the fact i publicly reached out instead of trying to reach out privately. the only reason i did it this way was because there was no available contact on their main site and the email i could find engineering@a16z.com bounced my emails
That's a clever lifehack to save your company money, by not having any way to privately contact engineering all bug bounties will have to be reported publicly which means you don't need to pay anything.
- bufferoverflow 2y agoBut it also teaches security researchers to sell that info next time instead of reporting.
- reducesuffering 2y agoSeriously, if anyone from a16z is reading this, all you're doing is incentivizing the next exploit to be sold and used against you.
- chefandy 2y agoAll sorts of cleverness going on there. I'll bet they saved a ton of money on development by lowballing people on fiverr or whatever they did, and indirectly they'll also save a ton on bookkeeping when a russian ransomware group effortlessly takes them for everything they have.
- HelloNurse 2y agoEven more bookkeeping will be saved with lost business opportunities.
- cqqxo4zV46cp 2y agoWith all the money a16z funnelling into the Trump campaign as it is, yada yada, I’m too lazy to make the rest of the line.
- nlh 2y agoCounterpoint: OP is a security researcher and couldn’t find a single human email address at one of the most well-known VC firms on the planet? LinkedIn? Twitter? Facebook friends? Come on. They’re not hard to reach if one really wants to. (Note: I still think A16Z should have paid them.)
- asopd 2y agoExactly, if he even just browsed their website a bit he'd have stumbled across loads of email addresses that could have been a useful point of contact.
- deleted 2y ago[deleted]
- dmix 2y agoIt’s more fun getting attention by doing it publicly and being the victim (security researchers love hitting the 'nobody respects us' button) than putting basic effort in. A single email bouncing is frustrating of course, but he then posted that an easily found vulnerability existed on Twitter, while a16z: - has a contact page page https://a16z.com/connect/ https://a16z.com/connect/ with 4x emails to their offices at the bottom (despite claims the main site had no other emails) - links to their Twitter where DMs are open https://x.com/a16z https://x.com/a16z same with instagram, FB, and linkedin, all open it would be easy to just email all of them at once and waiting a couple days to see if it gets escalated.
- asopd 2y ago[flagged]
- mynameisvlad 2y agoWhy should it be an onus on the researcher to find this information? It should be plainly provided in the first place. Someone shouldn’t have to jump through hoops to help the company secure its resources. That is not how this works.
- hugoromano 2y agoThis what you expect from VCs. I always prefer to report these incidents to GDPR authorities if user data is leaked. Then they pay the fines and some get a criminal record. Money is something VCs “print” and manipulate.
- istinetz 2y ago>Implying the Eu will actually do anything at all whatsoever upon reporting a gdpr issue >Money is something VCs “print” and manipulate. You wot m8
- hugoromano 2y agoIt is the member state authority, although EU GDPR is a Directive, is up to the member state. It doesn’t just apply to the EU, it can be UK ICO.
- istinetz 2y agoI have literally seen EU institutions fragrantly break GDPR
- deleted 2y ago[deleted]
- deleted 2y ago[deleted]
- paxys 2y agoThe company doesn't need a "hack" to not pay money. If they don't have a published bug bounty program then they owe nothing. They also have contact email addresses listed at the bottom of https://a16z.com/connect https://a16z.com/connect, which the researcher conveniently missed. They were looking for clout, not responsible disclosure.
- rvnx 2y agoLet's imagine your backpack is open. It's polite to say thanks if someone informs you that you accidentally left your backpack open. But in no way you are supposed to give them anything. Even further, some people take precious things from your backpack (trying to exploit the issue) and then come back to you asking for money; claiming they are nice people. This is non-sense.
- rdedev 2y agoIt's not the same. Figuring out a bagpack is open takes no effort. Finding a backdoor takes a lot of effort.
- TheRealPomax 2y agoNot when you find it on first "inspect element". That really is the equivalent of looking through someone's window and seeing their bank information and credits cards just lying in full view of anyone who'd look in.
- IshKebab 2y agoTerrible analogy. This is more like someone returning your wallet full of cash, on live TV. You aren't legally obligated to give them anything, but it sure is a dick move not to and good luck getting your wallet back next time you drop it if you don't.
- abejfehr 2y agoWhy will giving someone a cash reward mean you have a better chance of getting your wallet back in the future?
- deleted 2y ago[deleted]
- latexr 2y agoDo it enough times and you’ll be known for not paying any bounties, which makes people less likely to report issues they find.
- jazzdev 2y agoA post to HN with a query for how to get in touch with a16z engineering probably would have been fruitful.