3 ms·
As someone on the other side - we get spurious reports and people who cause DoS but only for that account in non-realistic scenarios regularly. Unfortunately it
by authorfly 2y ago
As someone on the other side - we get spurious reports and people who cause DoS but only for that account in non-realistic scenarios regularly. Unfortunately it is hard to tell the two apart or wise to get into debates about these topics - people start demanding money for "issues" you and every other web host in your industry is aware of (for example client side XSS modifying what appears on the screen... yes, really, they'll argue for cash).
- hannob 2y ago> Unfortunately it is hard to tell the two apart That's kinda a "you had one job" situation. Yes, it's hard to review security reports, and separate legit ones from bogus ones. But that's what these plattforms advertise they do. They regularly do a very bad job.
- bornfreddy 2y agoI think you misunderstood GP: > Unfortunately it is hard for the reporter to tell the two apart
- bugtodiffer 2y ago[flagged]
- fouc 2y ago>As someone on the other side that's the reviewer of the report, it's actually: > Unfortunately it is hard for the reviewer to tell the two apart
- bawolff 2y ago> That's kinda a "you had one job" situation. Yes, it's hard to review security reports, and separate legit ones from bogus ones. Security engineers aren't telepaths. Yes sometimes reviewers dont do a good job, but i think you are severely underestimating how incomprehensible incoming reports can be sometimes. It is not always worth it to spend 6 hours trying to figure out what someone is talking about.
- ryandrake 2y ago> Yes sometimes reviewers dont do a good job, but i think you are severely underestimating how incomprehensible incoming reports can be sometimes. Yes, and this also goes for bugs filed by the public, sometimes comments/requests in public Open Source projects. There are lots of examples of incomprehensible communication and then there's also argumentative communication (that usually gets increasingly argumentative and ad hominem as the reply chain continues). Based on viewing a sampling of public bug reports my company gets (including security incident reports), I would not want to be the agent who acts as liaison by replying and clarifying with the bug reporter. Most public reports are polite and constructive but it's shocking how high a percentage are not, and become increasingly unprofessional as the discussion continues.
- ta988 2y agoI can confirm that, we have had extremely annoying ones but they are a minority. Some of the participants are really good and that compensates.