A Bug in the Bug Bounty
engineering.prezi.com
A Bug in the Bug Bounty
1–10 of 37 posts
Re: A Bug in the Bug Bounty
#2"We greatly value this feedback."
Weak sauce. Shubham's disclosure saved Prezi from a future nightmare. If they're not going to pay him from the bug bounty coffers, they should at least try and sound more like grateful humans rather than a pissy HR department trying to do damage control.
Re: A Bug in the Bug Bounty
#3Prezi's apparently trying to cover their posteriors in the wake of Shubham's disclosure and subsequent snub ( http://blog.shubh.am/prezi-bug-bounty/ ). "We greatly value this feedback." Weak sauce. Shubham's disclosure saved Prezi from a future nightmare. If they're not going to pay him from the bug bounty coffers, they should at least try and sound more like grateful humans rather than a pissy HR department trying t…
Re: A Bug in the Bug Bounty
#4Re: A Bug in the Bug Bounty
#5Prezi's apparently trying to cover their posteriors in the wake of Shubham's disclosure and subsequent snub ( http://blog.shubh.am/prezi-bug-bounty/ ). "We greatly value this feedback." Weak sauce. Shubham's disclosure saved Prezi from a future nightmare. If they're not going to pay him from the bug bounty coffers, they should at least try and sound more like grateful humans rather than a pissy HR department trying t…
This means Shubham will get the bounty.
Re: A Bug in the Bug Bounty
#6There's plenty of non-entities that get reported: Failures of XSS protections on data that is actually public, vulnerabilities on vendors sites that don't impact your data, etc. Those should be dealt with with a polite thank you. Everything else should be valid, and everything else should be paid. Possibly not high-tier paid. Have your security team (You don't have a security team? Make one, even if it's just the coder from your team who has the most experience) triage and report. Fix things, or don't, but don't be an asshole and try to downplay real issues.
Re: A Bug in the Bug Bounty
#7Prezi's apparently trying to cover their posteriors in the wake of Shubham's disclosure and subsequent snub ( http://blog.shubh.am/prezi-bug-bounty/ ). "We greatly value this feedback." Weak sauce. Shubham's disclosure saved Prezi from a future nightmare. If they're not going to pay him from the bug bounty coffers, they should at least try and sound more like grateful humans rather than a pissy HR department trying t…
Anyways, they did try and get it right, by emailing me an apology as well as responding to my constructive criticism.
Before shubham posted anything.
Re: A Bug in the Bug Bounty
#8Prezi's apparently trying to cover their posteriors in the wake of Shubham's disclosure and subsequent snub ( http://blog.shubh.am/prezi-bug-bounty/ ). "We greatly value this feedback." Weak sauce. Shubham's disclosure saved Prezi from a future nightmare. If they're not going to pay him from the bug bounty coffers, they should at least try and sound more like grateful humans rather than a pissy HR department trying t…
1: http://blog.shubh.am/wp-content/uploads/2013/12/LetterLog_Pr...
Re: A Bug in the Bug Bounty
#9Prezi's apparently trying to cover their posteriors in the wake of Shubham's disclosure and subsequent snub ( http://blog.shubh.am/prezi-bug-bounty/ ). "We greatly value this feedback." Weak sauce. Shubham's disclosure saved Prezi from a future nightmare. If they're not going to pay him from the bug bounty coffers, they should at least try and sound more like grateful humans rather than a pissy HR department trying t…
"To improve the program from now on we will reward bug hunters who find bugs outside of the scope provided that they do not violate our users’ information and that their report triggers us to improve our code base. We will also retroactively check to see if other reports found issues that fall into this category." This means Shubham will get the bounty.
Re: A Bug in the Bug Bounty
#10Prezi's apparently trying to cover their posteriors in the wake of Shubham's disclosure and subsequent snub ( http://blog.shubh.am/prezi-bug-bounty/ ). "We greatly value this feedback." Weak sauce. Shubham's disclosure saved Prezi from a future nightmare. If they're not going to pay him from the bug bounty coffers, they should at least try and sound more like grateful humans rather than a pissy HR department trying t…
"To improve the program from now on we will reward bug hunters who find bugs outside of the scope provided that they do not violate our users’ information and that their report triggers us to improve our code base. We will also retroactively check to see if other reports found issues that fall into this category." This means Shubham will get the bounty.