Hacker News new | past | comments | ask | show | jobs | submit login

Depending on the severity of your finding, your report could wake up a senior security engineer.

When your report is out of scope, Google will not ignore your report. When there is a non-serious bug, you get acknowleged in the bug report they file internally. Finally, when they can not replicate your finding, they will communicate that with you and stay patient until they can either replicate or close your report.

Edit: forgot to add that they raised the bounty with another 2k ("we updated our payouts") and they invited me to their Blackhat booth 1 year later.




Interesting. What'd you find? :)


Apparently I was part of a test where input sanitization was turned off. Reported and fixed before they could push it live.

Very "monkey on a typewriter". I was not even looking for security bugs, but studying usage of maia.css.

http://aster.or.jp/conference/icst2017/program/jmicco-keynot...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: