lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Thu, 3 Oct 2013 10:06:38 +0100
From: Benji <me@...ji.com>
To: adam <adam@...sy.net>
Cc: Full-Disclosure <full-disclosure@...ts.grok.org.uk>
Subject: Re: Serious Yahoo bug discovered. Researchers
 rewarded with $12.50

Semi related, I'd like to know at what $ amount you guys value your ability
to type variations of ' "><script>alert(1)</script> ' . I value mine at
around $1000 a time because the characters are made of gold dust and I
spent most of my life learning to type.

:)


On Thu, Oct 3, 2013 at 9:09 AM, Benji <me@...ji.com> wrote:

> Yahoo have now started a big bounty formally instead of just trying to be
> nice (
> http://yahoodevelopers.tumblr.com/post/62953984019/so-im-the-guy-who-sent-the-t-shirt-out-as-a-thank-you).
>
> You can all go back to worrying about your bank balances now, and fitting
> the stereotype that all you (infosec) care about is money and not helping
> the world.
> On 3 Oct 2013 08:41, "Benji" <me@...ji.com> wrote:
>
>> No-one is making you do anything.
>>
>> If you don't feel like helping for free, like in the old days (2 years
>> ago..) then don't
>>
>> Jeeze, I remember when you guys used to moan that a company had no
>> security policy, now it's that "the amount offered is too low for me from a
>> company that has no formal bounty and was probably just ttrying to be nice
>> to gst out of bed for".
>>
>> Nice to meet you Justin Bieber of the infosec community.
>> On 3 Oct 2013 08:35, "adam" <adam@...sy.net> wrote:
>>
>>> bradon nailed it, it has nothing to do with entitlement, it has to do
>>> with incentive. $12.50 is not only _not_ incentive, but it's outright
>>> insulting, thus having the exact opposite effect.
>>>
>>>
>>> On Wed, Oct 2, 2013 at 10:34 AM, Jordon Bedwell <envygeeks@...il.com>wrote:
>>>
>>>> On Wed, Oct 2, 2013 at 10:32 AM, Ian Hayes <cthulhucalling@...il.com>
>>>> wrote:
>>>> > Sounds like someone has an overdeveloped sense of self-entitlement.
>>>>
>>>> Sounds like somebody is failing at trolling.
>>>>
>>>> _______________________________________________
>>>> Full-Disclosure - We believe in it.
>>>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>>>> Hosted and sponsored by Secunia - http://secunia.com/
>>>>
>>>
>>>
>>> _______________________________________________
>>> Full-Disclosure - We believe in it.
>>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>>> Hosted and sponsored by Secunia - http://secunia.com/
>>>
>>

Content of type "text/html" skipped

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ