TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Security researchers rewarded $12.50 voucher to buy Yahoo T-shirt

65 点作者 Titanous超过 11 年前

10 条评论

spicyj超过 11 年前
If Yahoo! had just sent the researchers t-shirts directly with thank-you notes, perhaps they still would have been disappointed with the reward but I doubt they (or we) would be as offended.<p>Funny how actual cash evokes different reactions.
评论 #6473080 未加载
pflats超过 11 年前
I&#x27;m sure the intention was something like, &quot;Hey, we should send them a thank you package. T-shirts? But wait, we don&#x27;t know their size. Oh, hang on, I have an idea!&quot;<p>And then they end up looking like jerks.
uncoder0超过 11 年前
What&#x27;s XSS an usually worth? I&#x27;m guessing it varies by product and company but, I would venture to say about $500-1000.<p>Really puts the $12.50 in company store credit into perspective.
评论 #6473051 未加载
评论 #6473087 未加载
dromidas超过 11 年前
Yahoo CEO rename to Katherine Janeway. Fuck up seriously in the first episode, and now she&#x27;s going to have to spend the rest of her time cleaning up her mess.
leggo2m超过 11 年前
Welp, it&#x27;s better than being criminally prosecuted!
eli超过 11 年前
I don&#x27;t think reporting security bugs is a great way to become rich. If you <i>expect</i> to be compensated you should convince Yahoo to hire you.<p>Is this worse than the many companies that have never given anything to any reporter?
评论 #6473386 未加载
nly超过 11 年前
Source:<p><a href="https://www.htbridge.com/news/what_s_your_email_security_worth_12_dollars_and_50_cents_according_to_yahoo.html" rel="nofollow">https:&#x2F;&#x2F;www.htbridge.com&#x2F;news&#x2F;what_s_your_email_security_wor...</a>
fmavituna超过 11 年前
Times have changed. Back in the day all we hoped was not getting sued for reporting a bug and now we are actually defaming companies who are not giving away good enough bounties.<p>It&#x27;s great to see that we came to this point.
wesleyac超过 11 年前
Personally, I&#x27;d <i>prefer</i> a little &quot;Thank You&quot; on some Yahoo site.<p>$12.50 seems insulting. &quot;Oh, your time is worth $12.50 to us, but thanks for disclosing a huge XSS issue.&quot;
rdl超过 11 年前
I wonder if this is why I&#x27;ve been getting so much spam from Yahoo accounts (and actually sent from Yahoo&#x27;s servers, from legitimate accounts).