A little note about Slack’s Bug Bounty program
11–20 of 52 posts
Re: A little note about Slack’s Bug Bounty program
#12Re: A little note about Slack’s Bug Bounty program
#13User accounts and passwords are easy to reset and fix.
Credit cards are easy to reset and fix.
Years of private company discussion showing up in the wild? You're unlikely to ever recover.
Re: A little note about Slack’s Bug Bounty program
#14http://valleywag.gawker.com/slack-is-letting-anyone-peek-at-... https://news.ycombinator.com/item?id=8425799
Tbh, at this point I wouldn't be surprised if these "problems" occurred after someone discovered the bug and reported it.
Re: A little note about Slack’s Bug Bounty program
#15I read the PDFs of #39132 and #51179, and first, these are very clear and well written vulnerability reports. Props to the author for that, many times these reports can be extremely hard to follow and these are shining examples to the contrary. I found them easy to follow, enough details to reproduce, and quite valid issues. Second, I'll put my neck out here a bit and say, I find myself agreeing with the author's sta…
Re: A little note about Slack’s Bug Bounty program
#16I read the PDFs of #39132 and #51179, and first, these are very clear and well written vulnerability reports. Props to the author for that, many times these reports can be extremely hard to follow and these are shining examples to the contrary. I found them easy to follow, enough details to reproduce, and quite valid issues. Second, I'll put my neck out here a bit and say, I find myself agreeing with the author's sta…
On point 1, how do they even expect a researcher to know that some other researcher has found the exact same bug if it's not disclosed yet? This seems like a fake rule whose only possible effect is to suppress disclosure.
Re: A little note about Slack’s Bug Bounty program
#17I'm currently in charge of answering reporters on a HackerOne program and I can tell that the way Slack is managing its own is completely unacceptable. Those reports were really high quality ones, whenever I receive a report like that I cry of joy. If you run a bounty program you should: - Be ready to answer every single report on a short timeframe - Be fair and provide feedback to the reporter - Be nice, be thankful…
Re: A little note about Slack’s Bug Bounty program
#18I'm siding with the vulnerability researcher here. This is ridiculous. The spirit of a bug bounty program is for the company to incentivize a researcher to find bugs and work together to squash them. Maybe this more telling of HackerOne as a platform.
Re: A little note about Slack’s Bug Bounty program
#19It feels to me that Slack is trying to be all high-and-mighty/"no you're wrong, we're right [even though you're right]"
Re: A little note about Slack’s Bug Bounty program
#20Combined with their recent hack and their exposing of team names a few months ago, I'm becoming wary of using Slack. They don't seem to have a security-focused culture, and that's a massive problem for a communication service.
Sorry other organization – I hope you guys move off some time soon.