3 ms·
I am not 100% sure about the legal details, but Nexmo as a company has a bug bounty reward program, so I assume in our case it doesn't apply because we want to
by marcuzhn 11y ago
I am not 100% sure about the legal details, but Nexmo as a company has a bug bounty reward program, so I assume in our case it doesn't apply because we want to know what's wrong and we request responsible disclosure (usually after the fix is in production).
You can see it here: https://cobalt.io/nexmo https://cobalt.io/nexmo (yes, it isn't yet linked from our www).
- JosephRedfern 11y agoOnly API's seem to be listed as in-scope, though. dashboard.nexmo.com (as well as www., and many other subdomains) are explicitly listed as being out of scope :).
- marcuzhn 11y agoLOL I expected that. Simple reason: we have received a good number of reports for our dashboard and some of them are still open mostly because they are not top priority. Needless to say we accept all reports and reward them accordingly to severity. :)
- hluska 11y agoSo, let's see if I understand this. - Your website has no security page and setting this up is such a low priority that you have no ETA on when /security might exist. - You instead use a third party service to manage your security disclosures. Yet, you don't link to this site from your website. - A researcher tries to contact you again and again. He gets no reasonable response so after several months he posts on Hacker News. The Hacker News post finally gets a response, yet you expect us to believe that you care about security???