3 ms·
You almost have to pull the site to stroke bounty hunter egos when you could just push a change to prod instead. If not, they are quick to bash you publicly.
by jollofricepeas 2y ago
You almost have to pull the site to stroke bounty hunter egos when you could just push a change to prod instead.
If not, they are quick to bash you publicly.
There’s too much hubris in the “professional” web app bug hunter community.
Generally, their attitude is very “look at these stupid developers,” “developers suck at security,” or “a conspiracy is happening because company X didn’t take their app down within 10 minutes of getting my email.” It’s much more nuanced than that.
I’d like to see:
1) more bounties and better paid bounties
2) less ego and much more professionalism and patience from “researchers”
Both would be better for consumers.
- hansvm 2y ago> when you could just push a change to prod instead. I wonder if there's an attack vector hiding where you induce a malicious bug via an illegitimate bounty and the developers' bias against inaction.
- azeirah 2y ago100%, hacking is as much technical prowess as it is social engineering.
- Thorrez 2y agoHow about this one: https://hackerone.com/reports/745324 https://hackerone.com/reports/745324 It's a $20k bounty for simply taking a cookie that a HackerOne employee accidentally pasted when responding to a different vuln report on HackerOne.