Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Every application has those bugs; on a software pentest, we'd sev:lo them.

Every application has a bug that can bring the whole application down for every user without owning a botnet? That comes often with a significant business cost, if someone exploits it. Many companies take them seriously. I have reported many as high and business has agreed. Not with HackerOne thought. If there is a bug where someone can make your whole product down with a single laptop isn't really something you can just ignore.



You can report a self-XSS sev:hi (and bounty hunters do) and get many orgs to take them seriously, because they don't have serious security practices. But DoS is generally sev:lo.


> You can report a self-XSS sev:hi (and bounty hunters do) and get many orgs to take them seriously, because they don't have serious security practices.

Which can be definitely high, if it can be triggered by giving specific URL, for example.

I think there is too much generalization happening here.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: