← Back to context

Comment by coldtea

2 years ago

>It's a bug bounty, not a "only if we have time to fix it" bounty

It's only a bug if it's not intended

I think a lot of developers and companies interpret "that's the way the code or process works" as intentional behavior, which is not always the case.

Do some companies intend for their platform to feature remote code execution?

  • Some might very well do. E.g. a company with a service for training hackers and security researchers.

    In this case the question is moot, as this doesn't involve remote code execution.

    • Make a general point, get a general answer.

      If the criteria for bug is "not intended", and that's solely judged by the company, then broken auth et al. suddenly become part of their product design.

      If it quacks like a bug, it's a bug.