this post was submitted on 13 Oct 2024
252 points (98.5% liked)

Technology

59347 readers
4401 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
top 5 comments
sorted by: hot top controversial new old
[–] [email protected] 90 points 1 month ago* (last edited 1 month ago) (1 children)

As I mentioned in another thread, about the same topic:

First Zendesk dismissed the report. Then as hackermondev (the hunter) contacted Zendesk's customers, the issue "magically" becomes relevant again, so they reopen the report and boss the hunter around to not disclose it with the affected parties.

Hackermondev did the morally right thing - from his PoV it was clear that Zendesk wasn't giving a flying fuck, so he contacted the affected parties.

All this "ackshyually it falls outside the scope of the hunt" boils down to a "not our problem lol". When you know that your services/goods have a flaw caused by a third party not doing the right thing (mail servers not dropping spoofed mails), and you can reasonably solve the flaw through your craft, not doing so is irresponsible. Doubly true if it the flaw is related to security, as in this case.

I'm glad that Zendesk likely lost way more than the 2k that they would've paid hackermondev for the hunt. And also that hackermondev got many times over that value from the affected companies.

[–] [email protected] 21 points 1 month ago

Such a small amount also for a company like Zendesk to pay this kid. Even if they initially did not acknowledge the issue, the moment they did.. all it would have taken was... "Hey kid, we revisited the issue and found that the bug you found was of higher importance than we originally thought, we will implement fixes for the issue and want to thank you by awarding you the bounty per our programme. Keep up the good work and let us know of you find more issues"... And ofc pay him the bounty.

[–] [email protected] 45 points 1 month ago

I work with Zendesk and this doesn’t surprise me at all - the product is janky and they’re much more interested in sales and squeezing a few more $$s from their clients than improving it or fixing issues

[–] [email protected] 43 points 1 month ago

Zendesk, Lastpass, All-The-Eggs-In-The-Cloud-Basket, all these products require dedicated internal teams to maintain anyway.

IT directors of old didn’t trust FOSS but did get rich signing over their company’s security to whoever showed up with a dog-and-pony show. Surprise - they’re just as lazy and cheap as you!

[–] [email protected] 31 points 1 month ago

And by a 15 year old no less! Keep up the awesome work young one, you’ll go far…