3 ms·
From what I can tell, the message is When you discover an exploit, only communicate with source (and pray they respond) or get sued. Seems like the position is
by 0x59 4mo ago
From what I can tell, the message is
When you discover an exploit, only communicate with source (and pray they respond) or get sued. Seems like the position is customers and stakeholders shouldn't be allowed access to this information.
- sigmoid10 4mo agoThat's actually very common even with respected bug bounty programs. Communicating exploits to anyone else (let alone the general public) will at the very least make you ineligible for rewards.
- 0x59 4mo agoIMO if you're participating in a BB program, you should abide by he rules set forth by the program. If you're not, then you don't have to.
- whstl 4mo agoSeems similar to what Microsoft is doing lately: https://www.cpomagazine.com/cyber-security/microsoft-doubles-down-on-opposition-to-public-disclosure-as-chaotic-eclipse-wave-of-zero-day-vulnerabilities-continues/ https://www.cpomagazine.com/cyber-security/microsoft-doubles...