Advertisement
Help Keep Boards Alive. Support us by going ad free today. See here: https://subscriptions.boards.ie/.
If we do not hit our goal we will be forced to close the site.

Current status: https://keepboardsalive.com/

Annual subs are best for most impact. If you are still undecided on going Ad Free - you can also donate using the Paypal Donate option. All contribution helps. Thank you.
https://www.boards.ie/group/1878-subscribers-forum

Private Group for paid up members of Boards.ie. Join the club.

Bug Bounty

  • 08-06-2020 05:09PM
    #1
    Moderators, Education Moderators Posts: 2,643 Mod ✭✭✭✭


    Hey ,

    Anyone here have experience of bug bountys ? I'm in the middle of submitting my first one(s) and getting a bit lost.

    Whats to stop a company taking your report, patching the flaw and then saying "we cant reproduce the issue"

    I know the issue existed because I created a video recreating the issue.

    Just wondering whats the normal procedure here, as I say, I'm new at this.


Comments

  • Closed Accounts Posts: 3,440 ✭✭✭Rodney Bathgate


    With social media and ability to screenshot or record I doubt any company would be stupid enough to try that.

    I’d be more worried that someone has steady submitted the issue and yours will be closed as a duplicate.


  • Moderators, Education Moderators Posts: 2,643 Mod ✭✭✭✭horgan_p


    With social media and ability to screenshot or record I doubt any company would be stupid enough to try that.

    I’d be more worried that someone has steady submitted the issue and yours will be closed as a duplicate.

    Do you have experience in this field ?
    If so I've a few more questions


  • Closed Accounts Posts: 3,440 ✭✭✭Rodney Bathgate


    No, but I work for a software company with open source and non-open source products. We have public JIRA projects and private ones. The lead time from an issue being identified / first reported to a fix being rolled out can be weeks or even months depending on resolution complexity and test cases, so there is a possibility they already are aware of the issue and working on a fix. Rushing out a fix can cause more problems than the original issue.


  • Moderators, Education Moderators Posts: 2,643 Mod ✭✭✭✭horgan_p


    With social media and ability to screenshot or record I doubt any company would be stupid enough to try that.

    I’d be more worried that someone has steady submitted the issue and yours will be closed as a duplicate.

    Do you have experience in this field ?
    If so I have a few more questions


Advertisement