Y
Hacker News
new
|
ask
|
show
|
jobs
by
eganist
2958 days ago
Sounds like a fix.
By the terms of the VRP it sounds like the reporter is owed a payout.
2 comments
kerng
2958 days ago
Bounty deserved, yes. Fixed? No, they only blocked his address, anyone else can still grab your info on their sites.
link
lallysingh
2958 days ago
Looks like it's blocked for everyone now
link
Buge
2957 days ago
It's blocked for people who aren't on the whitelist.
link
kerng
2957 days ago
That is interesting, do you have more info? I'd imagine the whitelist being quite enormous!
link
Buge
2957 days ago
I don't have any information besides what I've seen posted the comments here. For example this:
https://twitter.com/sirdarckcat/status/994867632355577862
link
acqq
2958 days ago
Exactly. If it was about "just whitelisted partners" he discovered it was actually "everybody." It's not different than discovering that instead of the password just an empty string is enough.
link