Earlier quoted context omitted.
> I think they acted pretty fairly They absolutely didn't. I don't get how there seems to be absolutely no human side to these cases. Guy discovers critical vulnerability and could have completely fucked the company over. Instead he responsibly reports it, and he gets back a big fuck you. How can you possibly think that's fair? The fact that it's out of scope only means they should give him an out of scope reward - m…
> Guy discovers critical vulnerability and could have completely fucked the company over. We all frequently have the opportunity to cause damage, but we don't get rewarded for _not_ doing so. I think Prezi may have given the cash reward if the pentester hadn't logged in and browsed around. They probably don't want to set a precedent (take the data you find, get cash reward). > ... because if the credentials were inva…
This seems to be key. Did he just verify the credentials, or did he poke around thereafter? If the latter, Prezi has a better case but they should have stated it more clearly.