Earlier quoted context omitted.
Legally, I don't think there's much "gray" in stealing source code that doesn't belong to you.
I doubt it could have been called 'stealing' if he only accessed what was posted publicly by the authors themselves at the time. Until he contacted Prezi, how could he be certain beyond any doubt that they weren't already aware of it? Could you explain that to me?
I found Prezi's source code
71–80 of 266 posts
Re: I found Prezi's source code
#72So let me get it straight, someone, aware of their bounty program or not, found their closed SOURCE CODE, and is getting a T-Shirt? How much do you value your own source code? at least 10,000$ right? ;) (probably much, much more) who cares about the scope, if someone found my wallet on the street which had 10,000$ in it, I would give them a bit more than a T-Shirt, I would buy them a whole wardrobe. Think if someone…
Re: I found Prezi's source code
#73Re: I found Prezi's source code
#74Earlier quoted context omitted.
Why is that? Weren't the login credentials posted publicly?
If you leave your door open and someone enters without your knowledge, would you call the police?
Re: I found Prezi's source code
#75[deleted]
Re: I found Prezi's source code
#76But I'm also quite upset with the fact that OP is outing the dev. Everybody makes mistakes, no need to out any individual developer because OP is pissed at the company management.
Re: I found Prezi's source code
#77Earlier quoted context omitted.
Sometimes people and companies have their heads stuck so far in procedures and policies that they can't see the forests from the trees. The Finder provided tremendous value by discovering this issues and reporting it responsibly. He certainly should be rewarded with something more substantial than swag. Would Prezi have preferred that the Finder just not report this issues?
It's not like they got him on some legalistic technicality. The bug bounty clearly doesn't cover the bug he reported. And I don't usually go looking for them, but if I come across a security problem (e.g. someone left login credentials unsecured in bitbucket) I would let them know because it's the right thing to do, not because I expect cash.
Re: I found Prezi's source code
#78Are bug bounties roughly the market value of security holes in software? I wonder if this guy or less scrupulous developers could make more for them on the black market?
Re: I found Prezi's source code
#79> "Anyways, they did try and get it right, by emailing me an apology as well as responding to my constructive criticism. This blog post, is by no means attempting to discourage people from participating from Prezi’s bug bounty, but rather just a blog post about how finding Prezi’s source code was not eligible for their bug bounty." Passive aggressive much? I think he should have got a bounty -- if not the official on…
Re: I found Prezi's source code
#80Earlier quoted context omitted.
Why is that? Weren't the login credentials posted publicly?
If you leave your door open and someone enters without your knowledge, would you call the police?
You did not enter the house you did not explore. You turned the key, the knob, and made sure the door would open a little.
Not something I would recommend, especially since the key had the address and the owner name and address attached to it.
But not as bad as someone entering the home and looking around.