HN user

sintheticlabs

37 karma
Posts4
Comments6
View on HN

For me, it boils down to two questions:

1. Does pursuing the vulnerability further benefit the research? 2. Would it cause any damage?

If the answers are yes and no, I'll happily see where it takes me and re-evaluate as I go on. With bug bounty programs it's generally expected that researchers are going to poke and prod at things which they otherwise shouldn't, although some programs do specifically state their objections to pursuing issues further. Facebook, for example, would rather you find an issue and report it straight away while others might admire your creativity to show exactly what an attacker could do.

I assume you mean in regards to employees posting internal information? A lot of people at Facebook have read both my articles so I feel there's been at least some light discussion about it. Whether or not it goes further than that, well, we'll see in about a year's time. :-)