3 ms·
I'm Marco and I work in the ops team at Nexmo. I have found your initial email to our Support team, and I can see that there have been some changes in our dashb
by marcuzhn 11y ago
I'm Marco and I work in the ops team at Nexmo. I have found your initial email to our Support team, and I can see that there have been some changes in our dashboard related to your report. I am not sure it's fixed because I don't have the details about the vulnerability you discovered, but I do know that initially we were resetting the user password straight away after a request. This is no longer the case - the email address now receives a reset link. If your report is still relevant despite this new procedure, I am very happy to receive the details.
Also, I would like to respond to the complaints that "we don't care about security". This is simply not true and we even use a bug bounty reward program. We do care and we accept reports through https://cobalt.io/ https://cobalt.io/ (ex CrowdCurity), so if you share with us your username/email on cobalt, we can add you to our program.
I totally agree we fucked up handling your report better back in may. I hope you are still willing to work with us!
- sebiw 11y agoHi Marco, I'm so happy I finally have a person to talk to that seems to understand me. Thanks for providing me the link to cobalt.io. I've never heard of that platform before. I just registered. My username is sebi I'd think it would strengthen the position that you care about security if you would dedicate a page on your site to security. Would really like to see something like that. Not only as a security researcher, but also as a customer of yours.
- marcuzhn 11y agoTotally agree and it's in the plan to add the security page (I don't have an ETA honestly). I will add you to our program shortly, thanks!
- jfrisby 11y agoWell, there's a "Report vulnerability" link right on the front page of nexmo.com as of right now...
- ohitsdom 11y agoSo is the vulnerability fixed or not?
- Taek 11y agoI worry that "we do care about security" is increasingly insufficient. It's one thing to care about security, another to think that you take it seriously, and another to actually take it seriously. Depending on the application, the amount of resources you should be expending on security is often times multiple times what a naive person would expect. Security is tricky and subtle, and most people don't realize how wrong they are when it comes to doing things securely.
- obilgic 11y agoI created an account long time ago which comes with x amount of $ for free. Somehow it got below the threshold, and Nexmo sends me an email every single day about my low account balance and tells me to add money. Since unsubscribing required me to login, now all the mail goes to spam folder. This is last 7 days: http://i.imgur.com/QhyMgCX.png http://i.imgur.com/QhyMgCX.png
- esbenfj 11y agoI'm Esben, cofounder and chief product officer at Cobalt (https://cobalt.io https://cobalt.io). I can confirm that Nexmo has been running a bug bounty program with us for more than a year now. They have rewarded researchers and are in general keeping a good response time through the program. They have now also added a link "Report Vulnerability" in the footer of nexmo.com linking directly to the program, making it easy for everyone to find it. You can read more about there work with us here if you are interested: https://cobalt.io/case-studies/nexmo https://cobalt.io/case-studies/nexmo