another bug bounty, another story of 'closed wontfix', where they dont pay out and fix the bug anyway
https://omarabid.com/hacker-one
bug bounties were a mistake
another bug bounty, another story of 'closed wontfix', where they dont pay out and fix the bug anyway
https://omarabid.com/hacker-one
bug bounties were a mistake
@Viss sounds about right :-/
this was... basically my experience with hackerone, the one time i used them.
the first 'hack the pentagon' bug bounty. where I found two bluecoat proxies that were misconfigured and permit traffic natted into their lan from the wan.
so i used proxychains, specified the wan addressess as http proxies, and contorted nmap to scan through it, and was getting tcp open/close hits from a 172 network inside what i was told later was "a training environment".
zero payout, no credit
but i got a coin?
im told it was the second-worst finding of the entire program, so youd think that would count for something, but oh well.
been sour on bugbounties since then. they seem to work on the 'carnival principle' - where a tiny handful of folks get MASSIVE PAYOUTS, and they gloat and brag about them, and thats the sorta marketing engine that keeps people trying them. most folks get peanuts, or nothing.
@Viss @paul_ipv6 lolsob
one of my pet peeves was the seemingly endless parade of congress-critters on CSPAN getting up to talk about something technical and starting with "i don't know how any of this techy stuff works at all but i think we should...".
no one goes to a "doctor" who starts with "i have no idea of how diseases or the body works and have no medical expertise but i think we should...".
@paul_ipv6 @ryanc rfk does
@ryanc so infuriatingly stupid. people who dont know how to computer shouldnt fucking be allowed to touch computers. not unless its to learn how to computer, and that would be on training computers.
the beatings will continue as long as the head of the cia uses an aol email address and politicians gloat about never reading emails and being complete nontechnical troglodytes
Internet is a series of pipes
@n_dimension @paul_ipv6 @Viss one time, on the way to hacker camp, I saw a big truck carrying a series of tubes
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.