4 ms·
"Closed the ticket" as what, though? "Duplicate, working on fixing" or "won't fix"? Because those are pretty different...
by InAnEmergency 12y ago
"Closed the ticket" as what, though? "Duplicate, working on fixing" or "won't fix"? Because those are pretty different...
- Sephr 12y agoDuplicates of non-public security vulnerabilities should be treated the same as the original reports (including the same rewards consideration process), especially if it was independently discovered. An unfixed security vulnerability is still an unfixed security vulnerability, no matter how many people discover it in the interim. By refusing to coordinate with the new submitter, the new submitter does not know if the vulnerability will ever be fixed and is reasonably justified in using public disclosure. The one case where refusing to coordinate with the new submitter is reasonable is when the new submitter learned about the vulnerability from the original submitter, which means that the original submitter has violated responsible disclosure. In that case, nobody would deserve a reward.
- oneweirdtrick 12y agoSo if it's marked as a duplicate, the original submitter loses visibility and is not even followed up with on whether there was a resolution? Is there a way to include an outside submitter on an original ticket or bug filed internally? I am pretty much clueless on the standard procedure of most big tech companies when it comes to these things.
- InAnEmergency 12y agoAs example, HackerOne allows you to link duplicate reports to the original, and all reporters are "thanked" when the issue is resolved. But I think in many cases reporters of duplicate issues do not get any follow up.
- InAnEmergency 12y ago> Duplicates of non-public security vulnerabilities should be treated the same as the original reports (including the same rewards consideration process), especially if it was independently discovered. This is rare for bug bounty rewards. All the programs I am aware of only reward the first reporter. > By refusing to coordinate with the new submitter, the new submitter does not know if the vulnerability will ever be fixed and is reasonably justified in using public disclosure. That's kind of what I'm pointing out here. We are missing information about what Facebook actually said and when it was said. The "we already know about it" response could mean "we know about it and are working on fixing it" or it could mean "we know about it and we don't care". In the former case, it is not responsible to publicly disclose the issue until it is fixed. In the later, it is. A separate scenario is if the company is taking a long time to fix the issue. This is obviously subjective, but in my opinion it is understandable for a reporter to publicly disclose a long-standing issue in an attempt to force the company to act.
- danielweber 12y agoYes, rewards to every submitter basically lead to the first guy telling N of his friends to all claim the bounty, too. It sucks to work for dozens of hours on something and then find out they already know about it, but the other option just leads to there being no bounties at all.