Live data from Hacker News

A Bug in the Bug Bounty

engineering.prezi.com

31–37 of 37 posts

Re: A Bug in the Bug Bounty

#31
post #8

Prezi's apparently trying to cover their posteriors in the wake of Shubham's disclosure and subsequent snub ( http://blog.shubh.am/prezi-bug-bounty/ ). "We greatly value this feedback." Weak sauce. Shubham's disclosure saved Prezi from a future nightmare. If they're not going to pay him from the bug bounty coffers, they should at least try and sound more like grateful humans rather than a pissy HR department trying t…

I think that's a bit harsh. I read the full email exchange he posted at the end of his article[1], and they went to some length to explain their position at the end of that exchange, and while I and many other wish it was different, I find their position understandable . With any number of past security submissions already deemed inadmissible for a bounty based on being out of bounds, how do they justify doing it in…

So they screwed up in the past and those screw ups should be used to justify this one, their position is understandable but in any case they can use their discretion to make up for it and it should not take one person to blow something out of proportion and force them to make this change.

Re: A Bug in the Bug Bounty

#33

Prezi's apparently trying to cover their posteriors in the wake of Shubham's disclosure and subsequent snub ( http://blog.shubh.am/prezi-bug-bounty/ ). "We greatly value this feedback." Weak sauce. Shubham's disclosure saved Prezi from a future nightmare. If they're not going to pay him from the bug bounty coffers, they should at least try and sound more like grateful humans rather than a pissy HR department trying t…

They are actually paying to Shubham. The original post by Shubham was updated: http://blog.shubh.am/prezi-bug-bounty/

Re: A Bug in the Bug Bounty

#34
post #18

Kudos to Prezi. They were not obligated to respond this way but they chose to, and I think it is the best response they could have made. I particularly like their statement that they would look to see whether anyone else had found volunteer abilities that also should be rewarded under the new program.

really? I think they were obligated - in the interest of not losing face among the hacker community after Shubham's post. If anything this was just a PR move more than anything else.

Re: A Bug in the Bug Bounty

#35
post #25

I haven't been following this story that closely but I just don't understand why they don't pay him outside the bug bounty. "Sorry this security hole wasn't in our bug bounty but we'd like to give you the reward anyway. Please sign these legal documents and let us know if you find anything else." There is so much you can do by just being reasonable. Like if Prezi said they can't officially acknowledge it under the bu…

You've been following the story so un-closely that you didn't even notice that this article says that's exactly what they are doing

Re: A Bug in the Bug Bounty

#36
post #26

Anecdotally I was snubbed at a younger age when the school district was looking for a security system to prevent manipulating school grades. My suggestion was to remove the disk pack (ok so it was a while ago) that contained student records while the students had access to the system via dialup, and replace it at night when the various accounting programs ran (attendance, grades, etc). Imagine my surprise when the co…

In today's world, you'd be expelled... https://www.google.com/#q=expelled+for+reporting+security+bu...

Doubtful. He didn't say he had hacked the grades or accessed the information in any way, just left a suggestion at the school's request.

Re: A Bug in the Bug Bounty

#37
post #8

Prezi's apparently trying to cover their posteriors in the wake of Shubham's disclosure and subsequent snub ( http://blog.shubh.am/prezi-bug-bounty/ ). "We greatly value this feedback." Weak sauce. Shubham's disclosure saved Prezi from a future nightmare. If they're not going to pay him from the bug bounty coffers, they should at least try and sound more like grateful humans rather than a pissy HR department trying t…

I think that's a bit harsh. I read the full email exchange he posted at the end of his article[1], and they went to some length to explain their position at the end of that exchange, and while I and many other wish it was different, I find their position understandable . With any number of past security submissions already deemed inadmissible for a bounty based on being out of bounds, how do they justify doing it in…

That their position is understandable doesn't make it any more reasonable.
Post reply on HN