Live data from Hacker News

A Bug in the Bug Bounty

engineering.prezi.com

1–10 of 37 posts

Re: A Bug in the Bug Bounty

#2
Prezi's apparently trying to cover their posteriors in the wake of Shubham's disclosure and subsequent snub ( http://blog.shubh.am/prezi-bug-bounty/ ).

"We greatly value this feedback."

Weak sauce. Shubham's disclosure saved Prezi from a future nightmare. If they're not going to pay him from the bug bounty coffers, they should at least try and sound more like grateful humans rather than a pissy HR department trying to do damage control.

Re: A Bug in the Bug Bounty

#3

Prezi's apparently trying to cover their posteriors in the wake of Shubham's disclosure and subsequent snub ( http://blog.shubh.am/prezi-bug-bounty/ ). "We greatly value this feedback." Weak sauce. Shubham's disclosure saved Prezi from a future nightmare. If they're not going to pay him from the bug bounty coffers, they should at least try and sound more like grateful humans rather than a pissy HR department trying t…

@MrZongle2 I agree.

Re: A Bug in the Bug Bounty

#5

Prezi's apparently trying to cover their posteriors in the wake of Shubham's disclosure and subsequent snub ( http://blog.shubh.am/prezi-bug-bounty/ ). "We greatly value this feedback." Weak sauce. Shubham's disclosure saved Prezi from a future nightmare. If they're not going to pay him from the bug bounty coffers, they should at least try and sound more like grateful humans rather than a pissy HR department trying t…

"To improve the program from now on we will reward bug hunters who find bugs outside of the scope provided that they do not violate our users’ information and that their report triggers us to improve our code base. We will also retroactively check to see if other reports found issues that fall into this category."

This means Shubham will get the bounty.

Re: A Bug in the Bug Bounty

#6
This is a trite response to an actual concern: Placing scope limits on bug bounties is meaningless and dangerous. Hackers will not respect your scope. The scope of a bug bounty program should always be "Anything that affects our, or our users, data or security".

There's plenty of non-entities that get reported: Failures of XSS protections on data that is actually public, vulnerabilities on vendors sites that don't impact your data, etc. Those should be dealt with with a polite thank you. Everything else should be valid, and everything else should be paid. Possibly not high-tier paid. Have your security team (You don't have a security team? Make one, even if it's just the coder from your team who has the most experience) triage and report. Fix things, or don't, but don't be an asshole and try to downplay real issues.

Re: A Bug in the Bug Bounty

#7

Prezi's apparently trying to cover their posteriors in the wake of Shubham's disclosure and subsequent snub ( http://blog.shubh.am/prezi-bug-bounty/ ). "We greatly value this feedback." Weak sauce. Shubham's disclosure saved Prezi from a future nightmare. If they're not going to pay him from the bug bounty coffers, they should at least try and sound more like grateful humans rather than a pissy HR department trying t…

Whilst waiting for their response, I realised that I would rather not accept their “swag”, and decided to instead, send off an email indicating why I wished to walk away with nothing....

Anyways, they did try and get it right, by emailing me an apology as well as responding to my constructive criticism.

Before shubham posted anything.

Re: A Bug in the Bug Bounty

#8

Prezi's apparently trying to cover their posteriors in the wake of Shubham's disclosure and subsequent snub ( http://blog.shubh.am/prezi-bug-bounty/ ). "We greatly value this feedback." Weak sauce. Shubham's disclosure saved Prezi from a future nightmare. If they're not going to pay him from the bug bounty coffers, they should at least try and sound more like grateful humans rather than a pissy HR department trying t…

I think that's a bit harsh. I read the full email exchange he posted at the end of his article[1], and they went to some length to explain their position at the end of that exchange, and while I and many other wish it was different, I find their position understandable. With any number of past security submissions already deemed inadmissible for a bounty based on being out of bounds, how do they justify doing it in this one case? I think they were heading this direction anyway, and if anything this just sped up the time frame.

1: http://blog.shubh.am/wp-content/uploads/2013/12/LetterLog_Pr...

Re: A Bug in the Bug Bounty

#9
post #5

Prezi's apparently trying to cover their posteriors in the wake of Shubham's disclosure and subsequent snub ( http://blog.shubh.am/prezi-bug-bounty/ ). "We greatly value this feedback." Weak sauce. Shubham's disclosure saved Prezi from a future nightmare. If they're not going to pay him from the bug bounty coffers, they should at least try and sound more like grateful humans rather than a pissy HR department trying t…

"To improve the program from now on we will reward bug hunters who find bugs outside of the scope provided that they do not violate our users’ information and that their report triggers us to improve our code base. We will also retroactively check to see if other reports found issues that fall into this category." This means Shubham will get the bounty.

I don't know about that: "from now on" seems to imply that in the future that will be the case.

Re: A Bug in the Bug Bounty

#10
post #5

Prezi's apparently trying to cover their posteriors in the wake of Shubham's disclosure and subsequent snub ( http://blog.shubh.am/prezi-bug-bounty/ ). "We greatly value this feedback." Weak sauce. Shubham's disclosure saved Prezi from a future nightmare. If they're not going to pay him from the bug bounty coffers, they should at least try and sound more like grateful humans rather than a pissy HR department trying t…

"To improve the program from now on we will reward bug hunters who find bugs outside of the scope provided that they do not violate our users’ information and that their report triggers us to improve our code base. We will also retroactively check to see if other reports found issues that fall into this category." This means Shubham will get the bounty.

retroactively.
Post reply on HN