3 ms·
> … hostile to security researchers who report these issues. Do you have an example?
by grahamjperrin 4mo ago
> … hostile to security researchers who report these issues.
Do you have an example?
- naturalmovement 4mo agoI have numerous examples of security researchers being hostile and impossible to work with (but cannot share them unfortunately).
- lukaslalinsky 4mo agoI don't have an example, but I know the pattern. You are working on your software, security researcher finds a bug, it's in your project, for you it's just another bug, but for them it's a point on their CV, so they make a theater about it, and expect priority in dealing with it. It must get tiring if you get many of these.
- krageon 4mo agoI've run a bug bounty program for a relatively large corporation and you are exactly right. It's worse in open source, because none of the developers owe a researcher their time. At least in a bug bounty program you've communicated willingness both ways already