|
|
|
|
|
by jorge_leria
4108 days ago
|
|
I'm currently in charge of answering reporters on a HackerOne program and I can tell that the way Slack is managing its own is completely unacceptable. Those reports were really high quality ones, whenever I receive a report like that I cry of joy. If you run a bounty program you should: - Be ready to answer every single report on a short timeframe - Be fair and provide feedback to the reporter - Be nice, be thankful and reward the researcher if they deserve it - Be patient with the duplicate reports and people just trying to get an unfair HoF Otherwise it may backfire you and eventually it will. |
|
These two issues (the hack and how they treat bug reporters) challenges the way I see slack as a company...