4 ms·
> Duplicates of non-public security vulnerabilities should be treated the same as the original reports (including the same rewards consideration process), espec
by InAnEmergency 12y ago
> Duplicates of non-public security vulnerabilities should be treated the same as the original reports (including the same rewards consideration process), especially if it was independently discovered.
This is rare for bug bounty rewards. All the programs I am aware of only reward the first reporter.
> By refusing to coordinate with the new submitter, the new submitter does not know if the vulnerability will ever be fixed and is reasonably justified in using public disclosure.
That's kind of what I'm pointing out here. We are missing information about what Facebook actually said and when it was said. The "we already know about it" response could mean "we know about it and are working on fixing it" or it could mean "we know about it and we don't care". In the former case, it is not responsible to publicly disclose the issue until it is fixed. In the later, it is.
A separate scenario is if the company is taking a long time to fix the issue. This is obviously subjective, but in my opinion it is understandable for a reporter to publicly disclose a long-standing issue in an attempt to force the company to act.
- danielweber 12y agoYes, rewards to every submitter basically lead to the first guy telling N of his friends to all claim the bounty, too. It sucks to work for dozens of hours on something and then find out they already know about it, but the other option just leads to there being no bounties at all.