Live data from Hacker News

I found Prezi's source code

blog.shubh.am

141–150 of 266 posts

Re: I found Prezi's source code

#141
post #129

Earlier quoted context omitted.

This is a no-brainer. Surely the risk of putting off skilled people from your bug bounty program due to the press from this could cost you a lot more than $500.

[deleted]

Bug bounties have a purpose and it is not to generate press or to be an equality outreach program. It is to find bugs.

If the rules are getting in the way of what the organisation is actually trying to use those rules for, then to be a stickler for rules is nuts when the same organisation wrote the rules in the first place and can change them at will.

edit - and if it is neccessary due to corporate legal waffle to always be a stickler for rules, then make a rule that details the protocol for exceptions.

Re: I found Prezi's source code

#142
post #90

Why even have a limited scope on bounty programs? (This is not the only time I've seen that.) Is it only to limit payout? Are their legal reasons? For example, their client tablet applications are ineligible. I just don't get the reasoning. In their position, I'd pay him the $500 and remove the idea of scope. I'm just curious if there's some counter-argument I'm not thinking about.

Having these kinds of rules on bug bounty programs is excellent for hackers though. If I wanted to hack Prezi I now have a lot of very useful information. 1) Prezi is not interested in blocking access to people who already have the ID of the presentation. This is good news since it means I can enumerate the IDs and get access to private presentations - some of which could have useful private data. 2) Prezi is not int…

It might simply be that they want to get some bugs first, then others later?

Re: I found Prezi's source code

#144
post #116

Why even have a limited scope on bounty programs? (This is not the only time I've seen that.) Is it only to limit payout? Are their legal reasons? For example, their client tablet applications are ineligible. I just don't get the reasoning. In their position, I'd pay him the $500 and remove the idea of scope. I'm just curious if there's some counter-argument I'm not thinking about.

[deleted]

You should stop talking and you were smart to delete that other comment.

I was wondering about what truly happened but now I get the impression that Prezi is officious and bureaucratic and I wonder what kind of customer support such an organization would offer:

"Our Terms of Service say we are not responsible for your lost data. Have a nice day and here's a T-Shirt."

Re: I found Prezi's source code

#145

Why even have a limited scope on bounty programs? (This is not the only time I've seen that.) Is it only to limit payout? Are their legal reasons? For example, their client tablet applications are ineligible. I just don't get the reasoning. In their position, I'd pay him the $500 and remove the idea of scope. I'm just curious if there's some counter-argument I'm not thinking about.

I can see why they would want to set up rules instead of allowing anything to happen. For example, if I was to set up a bounty I really wouldn't want people at random contacting current or former clients trying to phish for passwords; I completely understand this is a threat, but I would want to personally manage something like that. With that said, if something like this was found I'd pay the person. There's a point…

Well, this social engineering is what got kevin mitnick in jail

Re: I found Prezi's source code

#148
This would be unethical and I would never do it, but the interesting scenario would have been if he'd secretly pulled the source code and used his access to it to find a bunch more bugs. He would look like a genius and pocket a bunch more money.

Re: I found Prezi's source code

#149
post #116

Why even have a limited scope on bounty programs? (This is not the only time I've seen that.) Is it only to limit payout? Are their legal reasons? For example, their client tablet applications are ineligible. I just don't get the reasoning. In their position, I'd pay him the $500 and remove the idea of scope. I'm just curious if there's some counter-argument I'm not thinking about.

[deleted]

...external services that we don't have direct control over...

Adam B. has control over posting his passwords to public sites. ".hgignore" is handy.

Re: I found Prezi's source code

#150
post #76

This is definitely out of the scope of their "bughunt", although I think the guy should be rewarded anyway. But I'm also quite upset with the fact that OP is outing the dev. Everybody makes mistakes, no need to out any individual developer because OP is pissed at the company management.

I realised 2-3 hours after my blog post, and rushed to redact the last names from the post + pdf. I have now also redacted last names from the screenshots. Sorry about that! But thank you for letting me know. :)
Post reply on HN