Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Good article, but it's important to remember: this is fairly rare.

Good article, but it's important to remember: this is fairly rare.

Scheduled Pinned Locked Moved Uncategorized
7 Posts 3 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • iagox86@infosec.exchangeI This user is from outside of this forum
    iagox86@infosec.exchangeI This user is from outside of this forum
    iagox86@infosec.exchange
    wrote last edited by
    #1

    RE: https://chaos.social/@joeposaurus/116107550191010890

    Good article, but it's important to remember: this is fairly rare. Most organizations are grateful to get reports

    viss@mastodon.socialV g33katwork@infosec.exchangeG 2 Replies Last reply
    0
    • iagox86@infosec.exchangeI iagox86@infosec.exchange

      RE: https://chaos.social/@joeposaurus/116107550191010890

      Good article, but it's important to remember: this is fairly rare. Most organizations are grateful to get reports

      viss@mastodon.socialV This user is from outside of this forum
      viss@mastodon.socialV This user is from outside of this forum
      viss@mastodon.social
      wrote last edited by
      #2

      @iagox86 this has not been my experience. in my experience, most orgs just flatly ignore you outright

      iagox86@infosec.exchangeI 1 Reply Last reply
      0
      • iagox86@infosec.exchangeI iagox86@infosec.exchange

        RE: https://chaos.social/@joeposaurus/116107550191010890

        Good article, but it's important to remember: this is fairly rare. Most organizations are grateful to get reports

        g33katwork@infosec.exchangeG This user is from outside of this forum
        g33katwork@infosec.exchangeG This user is from outside of this forum
        g33katwork@infosec.exchange
        wrote last edited by
        #3

        @iagox86 It feels relatively common in Germany. Laws and legal uncertainties aren't helping ether.
        I don't disclose anything privately to vendors anymore. I have better things to do with my time and money than fighting useless lawsuits against companies that are beyond stupid.

        If something *really* impactful should be on my table, I'd proxy that through the CCC, but apart from that? Companies need to learn the hard way here. 🤷‍♂️

        Link Preview Image
        Modern Solution: Court of Appeal confirms guilt of security researcher

        On appeal by the programmer who uncovered a security vulnerability in software from Modern Solution, the regional court confirmed the penalty order.

        favicon

        heise online (www.heise.de)

        1 Reply Last reply
        0
        • viss@mastodon.socialV viss@mastodon.social

          @iagox86 this has not been my experience. in my experience, most orgs just flatly ignore you outright

          iagox86@infosec.exchangeI This user is from outside of this forum
          iagox86@infosec.exchangeI This user is from outside of this forum
          iagox86@infosec.exchange
          wrote last edited by
          #4

          @Viss interesting! I've done research for a few years now and that hasn't been my experience - most of the time it goes well. I've even launderered vulns for others to keep their name off of it

          The biggest problem is companies that insist you have to use their bounty which builds in an NDA

          viss@mastodon.socialV 1 Reply Last reply
          0
          • iagox86@infosec.exchangeI iagox86@infosec.exchange

            @Viss interesting! I've done research for a few years now and that hasn't been my experience - most of the time it goes well. I've even launderered vulns for others to keep their name off of it

            The biggest problem is companies that insist you have to use their bounty which builds in an NDA

            viss@mastodon.socialV This user is from outside of this forum
            viss@mastodon.socialV This user is from outside of this forum
            viss@mastodon.social
            wrote last edited by
            #5

            @iagox86 admittedly, its been a while since i bothered, i tried sending openai bugs and they said 'lol out of scope'. the whole premise is flawed. we should stop doing work for free

            iagox86@infosec.exchangeI 1 Reply Last reply
            0
            • viss@mastodon.socialV viss@mastodon.social

              @iagox86 admittedly, its been a while since i bothered, i tried sending openai bugs and they said 'lol out of scope'. the whole premise is flawed. we should stop doing work for free

              iagox86@infosec.exchangeI This user is from outside of this forum
              iagox86@infosec.exchangeI This user is from outside of this forum
              iagox86@infosec.exchange
              wrote last edited by
              #6

              @Viss when I'm told it's out of scope, I just verify that it's permission to publish

              It's not really "free", because I own the results and will publish it

              viss@mastodon.socialV 1 Reply Last reply
              0
              • iagox86@infosec.exchangeI iagox86@infosec.exchange

                @Viss when I'm told it's out of scope, I just verify that it's permission to publish

                It's not really "free", because I own the results and will publish it

                viss@mastodon.socialV This user is from outside of this forum
                viss@mastodon.socialV This user is from outside of this forum
                viss@mastodon.social
                wrote last edited by
                #7

                @iagox86 but they get your work for free and they fix the bug. its functionally equivalent to donating free consulting hours. the fact you can publish is just the fringe benefit

                1 Reply Last reply
                0
                Reply
                • Reply as topic
                Log in to reply
                • Oldest to Newest
                • Newest to Oldest
                • Most Votes


                • Login

                • Login or register to search.
                • First post
                  Last post
                0
                • Categories
                • Recent
                • Tags
                • Popular
                • World
                • Users
                • Groups