Apparently people are now holding on to low-medium-high bugs and submitting only crits because otherwise they get less invites on BB platforms? (heard this about H1, but probably true for others). Algorithmic failure if so
@Hogarth45_ Agreed, but I'm now hearing of people sitting on RXSS / SXSS / etc too. Admittedly I heard from a small percentage of hunters, but that doesn't seem like a net win for overall security
@Hogarth45_ If true, then I wonder how many vulns are going unreported by people who are not willing to get 2 accounts (which is against the rules iirc)
@MrTuxracer@plmaltais@Hacker0x01@Bugcrowd Unfortunately CVSS is hardly objective either, though. And it gets worse because half the bug bounty people and security teams do not fully understand the ratings for each field. Usually becomes a tug-of-war
Iβve loved watching how the @elonmusk@Twitter thing has impacted #InfoSec β meaning β people who do nothing but tweet all day and are defined by their egos and twitter identity have been freaking the fuck out β people who actually do the work really donβt care. Thoughts?
Can't wait for all the crybabies to finally "go to Mastodon" so my feed can stop being all about Elon and Twitter. If you're leaving, close your account and stop tweeting