Hacker News new | ask | show | jobs
by nikcub 4581 days ago
Exhibit A of why having a scope for bug bounties is a terrible idea. What is the point of testing your app for esoteric bugs when your entire source code and passwords can be Google dorked?
2 comments

Or for expanding the scope when you realize it's obviously too narrow.
> Exhibit A of why having a scope for bug bounties is a terrible idea.

Case closed.