Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
TomAnthony
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
91.
▲
by
TomAnthony
8y ago
That makes absolute sense to me, and I agree. However, it doesn't cover the aspect that some bugs are directly monetizable without needing to be sold (as was the case with my Google XML Sitemap exploit). Of course, there is a risk to d
92.
▲
by
TomAnthony
8y ago
OP here. I had exact same experience (and was aware of your story!). I also found a similar Google bug which didn't receive a bounty [1]. [1] http://www.tomanthony.co.uk/blog/confirm-google-users-email/
93.
▲
by
TomAnthony
8y ago
OP here. Really interesting to get your take on that. From my (far less security educated) POV the Google XML bug felt less risky from a monetisation angle. I guess the difference is between exploiting it yourself vs selling it. There was a
94.
▲
Facebook exploit – Confirm website visitor identities
(tomanthony.co.uk)
219 points
by
TomAnthony
8y ago
|
51 comments
95.
▲
by
TomAnthony
8y ago
DistilledODN is a bootstrapped SaaS startup unit inside a larger Digital Marketing agency. We are 5 core team members, looking to hire two more roles immediately. We literally created the market we operate in and are building an exciting pl
96.
▲
by
TomAnthony
8y ago
The problem is that often Open Redirects can be leveraged in unexpected ways, beyond the conventional attacks listed. I have previously been awarded a bug bounty by Google for an issue that leveraged open redirects on victim sites to hijack
97.
▲
Hijack the Google Login flow
(tomanthony.co.uk)
1 points
by
TomAnthony
8y ago
|
0 comments
98.
▲
by
TomAnthony
8y ago
In the Developer Tools, you can hit the 'Application' tab at the top then 'Cookies' on the left. Here you can delete cookies by domain (for dev etc.)! :)
99.
▲
by
TomAnthony
8y ago
I came across this on /r/webdev [1] and thought HN may find it informative and discussion worthy. This is related, I believe, to logging in to Gmail et al now logs you into Chrome the browser at the same time. I'm unsure if t
100.
▲
Chrome 69 will keep Google Cookies when you tell it to delete all cookies
(imgur.com)
4 points
by
TomAnthony
8y ago
|
3 comments
101.
▲
Expanding our Vulnerability Reward Program to combat platform abuse
(security.googleblog.com)
1 points
by
TomAnthony
8y ago
|
0 comments
102.
▲
Ultimate Hacking Keyboard
(ultimatehackingkeyboard.com)
317 points
by
TomAnthony
8y ago
|
292 comments
103.
▲
British Airways: Suspect code that hacked fliers ‘found’
(bbc.co.uk)
72 points
by
TomAnthony
8y ago
|
61 comments
104.
▲
Customer data theft – British Airways
(britishairways.com)
4 points
by
TomAnthony
8y ago
|
0 comments
105.
▲
by
TomAnthony
8y ago
Congrats on shipping this, it looks very intriguing! A few thoughts/ideas: - It would be helpful to see more product screenshots/videos of it in action. - It would also be useful to get more info on how this works and interacts wi
106.
▲
by
TomAnthony
8y ago
The problem is so clear in their write up that I can understand your thinking. However, in reality as this was going down it was probably not that clear cut. Especially when you consider that they are getting DoS attacks every 2-3 minutes -
107.
▲
by
TomAnthony
8y ago
(Reply to a deleted comment on the burden of compliance as a US business) If you truly do intend to take good care of your users’ data, then the goal should be to have you demonstrate that whilst making it as easy as possible for you to do
108.
▲
by
TomAnthony
8y ago
Your previous comments notwithstanding, this comment does have a legitimate point. If you truly do intend to take good care of your users’ data, then the goal should be to have you demonstrate that whilst making it as easy as possible for y
109.
▲
by
TomAnthony
8y ago
That was me. Google later upgraded the bounty to $5000. :) Article for those interested: http://www.tomanthony.co.uk/blog/google-xml-sitemap-auth-byp...
110.
▲
by
TomAnthony
8y ago
I think when (s)he said "paid for spam" which could be low quality out-sourced content. I assumed links to begin with too, but not no mention of links.
111.
▲
by
TomAnthony
8y ago
Putting aside the silly music, there is a serious discussion about how we allow such ill-qualified people to question people in this sort of setup.
112.
▲
by
TomAnthony
8y ago
TNW is a well respected and well established tech news site with a large team [0]. The author likely doesn't have direct control over the sharing buttons. I take your point, but on the other hand it is probably quite difficult to be aw
113.
▲
by
TomAnthony
9y ago
Thanks for your insights. I actually considered the same spot in the matrix as best fit, but also identified this sort of 'business logic' isn't a good fit anywhere in the matrix. I'm British so not good at kicking up a
114.
▲
by
TomAnthony
9y ago
Yeah, I'm not sure how well it fits in their matrix, though they do have a column for: This category includes products such as Google Search But it is probably intended to mean the front end of it, rather than the ranking algorithm.
115.
▲
by
TomAnthony
9y ago
I have discussed this with a bunch of people (and there is a discussion on Twitter right now [0]), and it seems quite unclear whether it would be illegal. It would certainly be unethical, and if it is illegal it may mean many other shady bl
116.
▲
by
TomAnthony
9y ago
Perhaps. We could argue the semantics of it, but it feels within the spirit of the VRP. It directly impacts the secure and correct functioning of a (the!) core Google service. The VRP page [0] talks about the "maximum impact" and
117.
▲
by
TomAnthony
9y ago
It is a good question. I wouldn't have monetised this and would have still report it, because doing so would hurt legitimate businesses (by pushing them out of the results). However, I have to admit it does nag at me a bit that the bou
118.
▲
by
TomAnthony
9y ago
There are a number of people lamenting about this 'missed opportunity' (and calling me some colourful names!) here: https://www.blackhatworld.com/seo/immediately-be-in-the-top-...
119.
▲
by
TomAnthony
9y ago
Maybe not millions, but you could make a decent chunk of money in a number of ways. The obvious 'easy' one would be to spin up affiliate sites and rank quickly and easily for competitive terms (with a site that does not deserve to
120.
▲
by
TomAnthony
9y ago
Yeah, the amount is quite geeky. For those interested in the other amounts they award (based on a matrix of severity and which part of Google): https://www.google.com/about/appsecurity/reward-program/
More ›