logoalt Hacker News

tptacektoday at 2:03 AM3 repliesview on HN

How's that? What do you think the purpose of a bug bounty is? If you think it's "to eradicate all bugs", no, very no.


Replies

Retr0idtoday at 2:14 AM

I don't expect an unbounded scope but I do expect it to cover the big scary headline items like RCE. Additionally, this can be exploited without MitM if you combine with e.g. a DNS cache poisoning attack. And they can still fix it even if they're not willing to pay a bounty.

show 1 reply
JJJollyjimtoday at 2:15 AM

This is the place they direct researchers to report bugs. If they don’t want to pay out for MITM, that’s fine, but they should still be taking out-of-scope reports seriously

show 1 reply
LoganDarktoday at 3:24 AM

A bug bounty should motivate exploitable bugs to be reported so that they can be fixed. IMO, if it refuses to accept certain kinds of bugs that can still be exploited, it's not working properly.

show 1 reply