cURL removes bug bounties
1–10 of 271 posts
Re: cURL removes bug bounties
#2https://gist.github.com/bagder/07f7581f6e3d78ef37dfbfc81fd1d...
Re: cURL removes bug bounties
#3Re: cURL removes bug bounties
#4A list of the slop if anyone is interested: https://gist.github.com/bagder/07f7581f6e3d78ef37dfbfc81fd1d...
Seeing Bard mentioned as an LLM takes me back :)
Re: cURL removes bug bounties
#5Then again, I once submitted a bug report to my bank, because the login method could be switched from password+pin to pin only, when not logged in, and they closed it as "works as intended", because they had decided that an optional password was more convenient than a required password. (And that's not even getting into the difference between real two-factor authentication the some-factor one-and-a-half-times they had implemented by adding a PIN to a password login.) I've since learned that anything heavily regulated like hospitals and banks will have security procedures catering to compliance, not actual security.
Assuming the host of the bug bounty program is operating in good faith, adding some kind of barrier to entry or punishment for untested entries will weed out submitters acting in bad faith.
Re: cURL removes bug bounties
#6Re: cURL removes bug bounties
#7Re: cURL removes bug bounties
#8Re: cURL removes bug bounties
#9Re: cURL removes bug bounties
#10Just use an LLM to weed them out. What’s so hard about that?
Brave new world we got there.