“We found PayPal vulnerabilities and PayPal punished us for it”
1–10 of 337 posts
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#2That seems like a good way to make sure nobody trusts your business. What say you, hackerone? How can anyone trust this business acting against what ostensibly is its core functions.
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#3Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#4Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#5If the analysts are just other users, then it definitely sounds like there is a problem.
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#6>When we pushed the HackerOne staff for clarification on these issues, they removed points from our Reputation scores, relegating our profiles to a suspicious, spammy level. This happened even when the issue was eventually patched, although we received no bounty, credit, or even a thanks. Instead, we got our Reputation scores (which start out at 100) negatively impacted, leaving us worse off than if we’d reported not…
> When we submitted this to HackerOne, they responded that this is an “out-of-scope” issue since it requires stolen PayPal accounts. As such, they closed the issue as Not Applicable, costing us 5 reputation points in the process.
But Paypal's policy really couldn't be clearer:
> Out-of-Scope Vulnerabilities
> Vulnerabilities involving stolen credentials or physical access to a device
( https://hackerone.com/paypal )
If Paypal says "don't send us this type of report", and you send one anyway, are you really surprised when your account gets a warning attached saying "this person usually files low-value reports"?
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#7A dupe costs points?! On bugcrowd you GET points for dupes...
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#8Are hackerone analysts employees of the company? If so the conclusion drawn sounds like complete bs. If the analysts are just other users, then it definitely sounds like there is a problem.
"When they aren’t triaging reports on our platform, they are spending time on their own bug bounty hunts."
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#9I've seen several stories about how HackerOne doesn't pay out bug bounties when bugs are reported. I, for one, wouldn't submit bugs/PoC to them, and I would actively, publically, and immediately disclose bugs that affect anybody who is a client of HackerOne.
Sadly you can't feed your children from media drama.
Maybe, in the long run, but it's more likely to get sued.
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#10Are hackerone analysts employees of the company? If so the conclusion drawn sounds like complete bs. If the analysts are just other users, then it definitely sounds like there is a problem.
The screenshots in this article show a "HackerOne Staff" stamp, so those triagers are employees of H1.