Live data from Hacker News

Viewing profile — franjkovic

franjkovic

HN member
Joined
Sun, Oct 20, 2013, 12:43 AM UTC
HN karma
1,114
Public activity
44 items

About franjkovic

[ my public key: https://keybase.io/josipfranjkovic; my proof: https://keybase.io/josipfranjkovic/sigs/4EYnl7a6Vko4DGKQFypdzXwAxT-YnFN8DEc5X34RttQ ]

My security blog: https://www.josipfranjkovic.com

Recent public activity

  1. story
  2. story
  3. story
  4. story
  5. story
  6. comment
    Comment #12149157

    Every Twitter's bounty amount is divisible by 140.

  7. comment
    Comment #12126491

    I wanted to move from Blogspot to a personal domain, but kept delaying it for a long time.

  8. comment
    Comment #12126104

    >how many hours did you spend researching this? Two to three hours discovering and writing the initial report, couple more hours (unsuccessfully) trying to escalate it using pre-ap…

  9. comment
    Comment #12125921

    The bug was reported on December 8th, 2015 and fixed on February 18th, 2016 which is an unusually long time for Facebook. The bounty reached my account during the middle of March, …

  10. story
  11. story
  12. story
  13. comment
    Comment #11706200

    The post is interesting, but I do not know why people assume they would get a bounty for a security report if the company does not have responsible disclosure / bounty program.

  14. story
  15. comment
    Comment #10755338

    I'd say it does. Not interact with other accounts without the consent of their owners. Edit: whoops I mis-read this a bit, but the point still stands - he escalated using AWS keypa…

  16. comment
  17. story
  18. story
  19. story
  20. story
  21. comment
    Comment #9444089

    I think they did not reward me because you cannot really hurt anyone by having multiple usernames.

  22. comment
    Comment #9444056

    Thanks! I reported the bug to security@ email, and one of your team's members replied on the same day (January 6th). Either way, good job on fixing this really fast. I wish more te…

  23. comment
    Comment #9444037

    Facebook puts out stats from their bug bounty program once a year. Most of bugs are invalid reports - in 2013 they had 14,763 reports, with 687 being valid. ( https://www.fb.com/81…

  24. comment
    Comment #9444002

    The bounty actually surprised me, too. I expected between $1000-$2000. That is one of reasons I like reporting bugs to Facebook - they pay really good, critical bugs are fixed real…

  25. story