Forgot your password?
typodupeerror

+ - Security Researchers Rewarded with $12.50 Voucher to Buy Yahoo T-Shirt 2

Submitted by Hugh Pickens DOT Com
Hugh Pickens DOT Com (2995471) writes "More and more companies are offering Bug Bounty Programs remunerating security researchers for reporting vulnerabilities and weaknesses in their applications and software. Now Security analyst Graham Cluley writes that researchers at High-Tech Bridge informed Yahoo’s Security Team about three cross-site scripting (XSS) vulnerabilities affecting the ecom.yahoo.com and adserver.yahoo.com domains. According to High-Tech Bridge, each of the vulnerabilities could compromise *any* @yahoo.com email account. All that was required was that the victim, while logged into Yahoo, should click on a specially-crafted link received in an email. Forty-eight hours later, Yahoo had patched all of the vulnerabilities and Yahoo’s security team responded, thanking the researchers and "offering the mighty bounty of err.. $12.50 per vulnerability," writes Cluley. But there was one catch. The $12.50 was given as a discount code that can only be used in the Yahoo Company Store, which sells Yahoo’s corporate t-shirts, cups, pens and other accessories. "Such a risible reward is unlikely to win Yahoo any friends and could – if anything – make it less likely that the site will gain the assistance of white-hats in future," wrote Cluley. “If Yahoo cannot afford to spend money on its corporate security, it should at least try to attract security researchers by other means," wrote Ilia Kolochenko, the CEO of High-Tech Bridge. "Otherwise, none of Yahoo’s customers can ever feel safe.”"
This discussion was created for logged-in users only, but now has been archived. No new comments can be posted.

Security Researchers Rewarded with $12.50 Voucher to Buy Yahoo T-Shirt

Comments Filter:
  • When I went to work for an aerospace company in 1972, well-documented suggestions that were adopted would get you a check for 10% of the estimated first-year savings...and some of those checks were very sweet. By about 1990, they would get you a voucher to pick an item from a gift catalog. The program brochure was illustrated with a line drawing of a guy's head and a thought balloon as he dreamed of a Dust Buster.

  • Receiving company t-shirts as a symbolic gesture/compensation for discovering vulnerabilities is not that unheard of. However, in those cases there is an actual t-shirt (sometimes personalized) sent as a gesture of recognition not a lousy voucher. I feel yahoo will make them whole in one or another to get some PR points with this story. In the end, I guess a voucher is still better than an army of lawyers coming after you.

Forty two.

Working...