3 ms·
They’re supposed to. Instead they have a reputation for telling researchers that their disclosure isn’t actually a vulnerability and doesn’t qualify for a boun
by transcriptase 4mo ago
They’re supposed to.
Instead they have a reputation for telling researchers that their disclosure isn’t actually a vulnerability and doesn’t qualify for a bounty or recognition, then quietly patching said non-vulnerability with a suspicious degree of urgency.
- jiggawatts 4mo agoHappened to me when I reported that I could get Azure to issue me a certificate for a domain I don’t own. Rejected, then quietly fixed a couple of months later.