Earlier quoted context omitted.
You can liquidate bitcoin in about 5 minutes using Coinbase.
took me a week to get my bitcoin.
I found Prezi's source code
211–220 of 266 posts
Re: I found Prezi's source code
#212What an asshole approach [1]. Please, next time someone find a critical bug in the system, don't bother emailing them; just post it on Twitter. [1] http://i.imgur.com/v3W9FD6.png
Re: I found Prezi's source code
#213I'm hp co-founder and CTO of prezi. We learn from our mistakes, we have changed the program: To improve the program from now on we will reward bug hunters who find bugs outside of the scope provided that they do not violate our users’ information and that their report triggers us to improve our code base. We will also retroactively check to see if other reports found issues that fall into this category. More info at…
Re: I found Prezi's source code
#214Earlier quoted context omitted.
> What is the gain in setting up a "Can you hack us?" and then make some parts out of scope?! It's not like a black hat hacker would go "Oh well, this isn't their usual domain, so It's not fair" -.- This suggests that anything less than perfect security is worthless. Which is better, having pentesters look for vulnerabilities in 50% of your surface area, or having pentesters look for vulnerabilities in 0% of your sur…
> This suggests that anything less than perfect security is worthless. Which is better, having pentesters look for vulnerabilities in 50% of your surface area, or having pentesters look for vulnerabilities in 0% of your surface area? Is this supposed to be rhetorical? Say you buy a really good front door for your house, and forget to put a back door on your house. I would say that testing the security of the front do…
I think your point is too extreme. Locking your front door is most definitely NOT a waste of time, because with that move alone, you've automatically protected yourself against the subset of attackers who don't think to try the back door. Are you still vulnerable? Yes, of course. But decidedly less so. As the OP said, 50% is better than 0%.
The real conversation that should be taking place is not whether or not a limited scope should exist (it should), but how far that scope should extend given the costs of extending it.
Re: I found Prezi's source code
#215Earlier quoted context omitted.
I doubt it could have been called 'stealing' if he only accessed what was posted publicly by the authors themselves at the time. Until he contacted Prezi, how could he be certain beyond any doubt that they weren't already aware of it? Could you explain that to me?
Using login in credentials that are not your own found in a public place to take source code is like finding someones house key on a park bench and coping their secret invention designs or trade secrets.
Re: I found Prezi's source code
#216Re: I found Prezi's source code
#217Earlier quoted context omitted.
But.. that can be said about any java (jar) programs class files. It is also not difficult to decipher the asm of a disassembled exe file, but to equate that with finding the source code of the program would be disingenuous.
You can drag drop that jar file into http://jd.benow.ca/ and in two clicks you have 100% of the source code, variable names and all. It's not the same as decompiling an C executable by any means.
Re: I found Prezi's source code
#218Re: I found Prezi's source code
#219Earlier quoted context omitted.
So because it was out of scope it means that it could not have harmed the company so he should have just left it there?
You're not entitled to a bounty just because you found a bug. Some companies offer these bounties and it's good that they do, but that doesn't mean every company is obliged to offer them, or that a company that offers bounties for some bugs is obliged to offer them for all bugs.
Re: I found Prezi's source code
#220Earlier quoted context omitted.
Leaked source code does not end a company. Tone back the melodrama. A legitimate company cannot use stolen code like that, and prezi isn't the type of service with ground breaking algorithms to copy into other code.
Sure, in that possibility, that is very true in that nobody could build a full fledged knockoff product. But, what concepts or features that could result in cheap knockoffs? Designed attacks? Password leaks and user privacy breaches? Customer information that can be sold to competitors? All of the bad PR and loss of business as a result?