Hacker News new | past | comments | ask | show | jobs | submit login

To give the benefit of the doubt, it appears he only contacted them less than 48 hours ago. Their first priority should correctly be to fix the problem. They could be discussing a bug bounty right now and just haven't finalized the email yet



American readers may not have noticed that the dates are in European DD/MM format, so they thought disclosure was Sept 1 rather than Jan 9.


I 100% saw it as MM/DD and was wondering why it took them three months to write up the vulnerability and a month to patch it.

Thanks for the clarification


“Thanks for coming to us with this, we’re looking at it right away” wouldn’t take a lot of time or commit then to anything




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: