top | item 43966635

(no title)

cobalt60 | 9 months ago

Why not disclose it as a responsible dev with contacts and move on.

discuss

order

pixl97|9 months ago

If a company is not responsible enough to follow up on security reports you should not follow up, but instead disclose it to the world.

flutas|9 months ago

tbh, I agree.

I've sent 2 big bugs like this, one Funimation and one for a dating app.

Funimation you could access anyones PII and shop orders, they ignored me until I sent a linkedin message to their CTO with his PII (CC number) in it.

The "dating" app well they were literally spewing private data (admin/mod notes, reports, private images, bcrytped password, ASIN, IP, etc) via a websocket on certain actions. I figured out those actions that triggered it, emailed them and within 12 hours they had fixed it and made a bug bounty program to pay me out of as a thank you.

Importantly, I also didn't use anyone else's data/account, I simply made another account that I attacked to prove. Yes it cost me a monthly sub ~$10 to do so. But they also refunded that.

shayanbahal|9 months ago

I think it took so long that I moved on, but you are right and I should have done that. Probably I'll take a look again to see if I can do it now :)