|
|
|
|
|
by zaroth
3620 days ago
|
|
Normally I like bike shedding about bug bounty payouts just about as much as complaints about paywalls. If you are going to go poking around someone's code for fun or profit, the terms of the bounty program are readily available [1] so you can't complain after the fact for earning the maximum payout. LastPass isn't Facebook, and they never claimed they would pay more than $1,000 even for a full compromise or RCE. On the other hand, using regexp to parse the URL when it's such an obviously security critical code path... just, why?! [1] - https://bugcrowd.com/lastpass |
|