5 ms·
>Further, had he been less than honest, he may have been able to leverage the code itself to find more than one $500 bug. I'm not sure I agree with this partic
by AGuyNamedChris 13y ago
>Further, had he been less than honest, he may have been able to leverage the code itself to find more than one $500 bug.
I'm not sure I agree with this particular argument, it essentially reduces the concept of a bug bounty to blackmail. This mindset is not a constructive one.
The tester should get rewarded for their hard work and helpfulness, not the decision to follow the law.
- Ensorceled 13y agoI think he meant scan the source code for security issues and then report those bugs one by one ...
- sophacles 13y agoThat is what I meant, I should have been more clear.
- Ensorceled 13y agoI thought it was pretty clear :-)
- octatone2 13y agoIt was perfectly clear, I don't know what the parent is on about with blackmail.
- Dylan16807 13y agoHow is that dishonest? It sounds like a great way to improve security and get bounties.
- antoinec 13y agoI'm sure (paying) customers will be totally fine with Prezi's source code being available to anyone that want to try to hack the site.
- Dylan16807 13y agoI fail to see how that has anything to do with honesty. The source was leaked accidentally.