Live data from Hacker News

How to send DMs on Twitter without permission

homakov.blogspot.com

11–20 of 60 posts

Re: How to send DMs on Twitter without permission

#11
post #10

This is the same guy who hacked GitHub (and Rails) with the multiple assignment hack, among other things.

homakov is as famous as PG on HN.

Where is he "as famous"?

On HN? Or somewhere else (if so where?) where he is "as famous as PG on HN".

If you mean he is as famous on HN as PG is on HN I don't think that is the case.

Re: How to send DMs on Twitter without permission

#12
> I wrote a full disclosure post 5 minutes after finding the bug because twitter doesn't reward "bounty hunters".

Companies without bug bounties don't deserve responsible disclosure? Twitter has a pretty clear way to reach them, and recognition is given on their page. If recognition isn't sufficient for responsible disclosure, how much money would be enough? I think bug bounty programs are great, but I don't think they should be mandatory.

https://about.twitter.com/company/security

Re: How to send DMs on Twitter without permission

#14
post #11
post #10

Earlier quoted context omitted.

homakov is as famous as PG on HN.

Where is he "as famous"? On HN? Or somewhere else (if so where?) where he is "as famous as PG on HN". If you mean he is as famous on HN as PG is on HN I don't think that is the case.

He means that the following are equivalent:

* How famous PG is in HN

* How famous homakov is in HN

Re: How to send DMs on Twitter without permission

#16
post #12

> I wrote a full disclosure post 5 minutes after finding the bug because twitter doesn't reward "bounty hunters". Companies without bug bounties don't deserve responsible disclosure? Twitter has a pretty clear way to reach them, and recognition is given on their page. If recognition isn't sufficient for responsible disclosure, how much money would be enough? I think bug bounty programs are great, but I don't think th…

> Companies without bug bounties don't deserve responsible disclosure?

That seems to be homakov's view, yes, and I can't say I don't understand his view.

Re: How to send DMs on Twitter without permission

#17
This is in line with a long laundry list of horribleness about user experience as related to DMs in my opinion. They don't work as expected, and quite honestly to me it feels like Twitter is running a campaign to destroy peoples' love of the DM in search of a Solution, maybe in preparation for a dm 2.0 or something.

Some of the experience elements of DM have been fixed on the iPhone, but last I checked, the problems on web desktop made me so annoyed that I stopped using DMs altogether.

Re: How to send DMs on Twitter without permission

#18
post #16
post #12

> I wrote a full disclosure post 5 minutes after finding the bug because twitter doesn't reward "bounty hunters". Companies without bug bounties don't deserve responsible disclosure? Twitter has a pretty clear way to reach them, and recognition is given on their page. If recognition isn't sufficient for responsible disclosure, how much money would be enough? I think bug bounty programs are great, but I don't think th…

> Companies without bug bounties don't deserve responsible disclosure? That seems to be homakov's view, yes, and I can't say I don't understand his view.

[deleted]

Re: How to send DMs on Twitter without permission

#19
post #16
post #12

> I wrote a full disclosure post 5 minutes after finding the bug because twitter doesn't reward "bounty hunters". Companies without bug bounties don't deserve responsible disclosure? Twitter has a pretty clear way to reach them, and recognition is given on their page. If recognition isn't sufficient for responsible disclosure, how much money would be enough? I think bug bounty programs are great, but I don't think th…

> Companies without bug bounties don't deserve responsible disclosure? That seems to be homakov's view, yes, and I can't say I don't understand his view.

Of course you understand it, but do you agree with it?

If you seek out bugs in a company's code with the expectation that you'll be rewarded for it, and then the company fails to reward you, I can see that it might be perceived as unfair, especially if the company indicated that such an expectation was reasonable.

If you happen across a bug in a company's code, and then publicize it because they aren't going to pay you money for it, that seems a little more like "blackmail." People really shouldn't orient their moral systems around money.

Post reply on HN