Hacker News new | ask | show | jobs
by transcriptase 17 days ago
They’re supposed to.

Instead they have a reputation for telling researchers that their disclosure isn’t actually a vulnerability and doesn’t qualify for a bounty or recognition, then quietly patching said non-vulnerability with a suspicious degree of urgency.

1 comments

Happened to me when I reported that I could get Azure to issue me a certificate for a domain I don’t own.

Rejected, then quietly fixed a couple of months later.