Prezi's apparently trying to cover their posteriors in the wake of Shubham's disclosure and subsequent snub ( http://blog.shubh.am/prezi-bug-bounty/ ). "We greatly value this feedback." Weak sauce. Shubham's disclosure saved Prezi from a future nightmare. If they're not going to pay him from the bug bounty coffers, they should at least try and sound more like grateful humans rather than a pissy HR department trying t…
I think that's a bit harsh. I read the full email exchange he posted at the end of his article[1], and they went to some length to explain their position at the end of that exchange, and while I and many other wish it was different, I find their position understandable . With any number of past security submissions already deemed inadmissible for a bounty based on being out of bounds, how do they justify doing it in…
A Bug in the Bug Bounty
31–37 of 37 posts
Re: A Bug in the Bug Bounty
#32Re: A Bug in the Bug Bounty
#33Prezi's apparently trying to cover their posteriors in the wake of Shubham's disclosure and subsequent snub ( http://blog.shubh.am/prezi-bug-bounty/ ). "We greatly value this feedback." Weak sauce. Shubham's disclosure saved Prezi from a future nightmare. If they're not going to pay him from the bug bounty coffers, they should at least try and sound more like grateful humans rather than a pissy HR department trying t…
Re: A Bug in the Bug Bounty
#34Kudos to Prezi. They were not obligated to respond this way but they chose to, and I think it is the best response they could have made. I particularly like their statement that they would look to see whether anyone else had found volunteer abilities that also should be rewarded under the new program.
Re: A Bug in the Bug Bounty
#35I haven't been following this story that closely but I just don't understand why they don't pay him outside the bug bounty. "Sorry this security hole wasn't in our bug bounty but we'd like to give you the reward anyway. Please sign these legal documents and let us know if you find anything else." There is so much you can do by just being reasonable. Like if Prezi said they can't officially acknowledge it under the bu…
Re: A Bug in the Bug Bounty
#36Anecdotally I was snubbed at a younger age when the school district was looking for a security system to prevent manipulating school grades. My suggestion was to remove the disk pack (ok so it was a while ago) that contained student records while the students had access to the system via dialup, and replace it at night when the various accounting programs ran (attendance, grades, etc). Imagine my surprise when the co…
In today's world, you'd be expelled... https://www.google.com/#q=expelled+for+reporting+security+bu...
Re: A Bug in the Bug Bounty
#37Prezi's apparently trying to cover their posteriors in the wake of Shubham's disclosure and subsequent snub ( http://blog.shubh.am/prezi-bug-bounty/ ). "We greatly value this feedback." Weak sauce. Shubham's disclosure saved Prezi from a future nightmare. If they're not going to pay him from the bug bounty coffers, they should at least try and sound more like grateful humans rather than a pissy HR department trying t…
I think that's a bit harsh. I read the full email exchange he posted at the end of his article[1], and they went to some length to explain their position at the end of that exchange, and while I and many other wish it was different, I find their position understandable . With any number of past security submissions already deemed inadmissible for a bounty based on being out of bounds, how do they justify doing it in…