Skip to content
DevMeme
6564 of 7590
Security Post #7194 · source on Telegram

Wholesome Hacker-Founder Exchange: Exploit Disclosed, Lifetime Membership Offered

Description

A screenshot of an email exchange between Phalgun from Simplehuman ([email protected]) and a user named Blake. Phalgun writes that he knows Blake found a way to bypass the subscription system, is impressed, and offers a lifetime membership in exchange for disclosure of the hack and stopping the bypass. Blake responds graciously, accepts the offer, agrees to share the technical details, and even discloses a second vulnerability as a show of good faith. The exchange includes a 'SORRY' sticker with a cute character. This is a heartwarming example of responsible disclosure handled respectfully by both parties

Comments

21
Anonymous ★ Top Pick The best penetration test is the one where the founder emails you saying 'I'm not even mad, that's impressive' and hands you a lifetime license
  1. Anonymous ★ Top Pick

    The best penetration test is the one where the founder emails you saying 'I'm not even mad, that's impressive' and hands you a lifetime license

  2. Anonymous

    Most companies send a C&D letter when you find an exploit. This one offered a lifetime subscription. It's the bug bounty equivalent of getting equity instead of a restraining order

  3. Anonymous

    Finally, a growth-hack that literally hacks growth metrics - good thing legal signed off with a lifetime coupon instead of a cease-and-desist

  4. Anonymous

    The rare moment when a company's bug bounty program is just 'please stop breaking our stuff and we'll give you free access' - essentially paying the ransomware in product licenses instead of Bitcoin

  5. Anonymous

    When your analytics show 10x user growth but it's actually one engineer with a subscription bypass and a for-loop - the SaaS equivalent of discovering your 'viral growth' was a single determined developer who really didn't want to pay $9.99/month. Props to both parties here: one for the creative session management exploit, the other for turning a potential PR nightmare into a teaching moment. This is what 'responsible disclosure' looks like when both sides have actually shipped production code - mutual respect, technical curiosity, and the understanding that today's vulnerability researcher might be tomorrow's security engineer. Plus, offering a lifetime membership is cheaper than hiring a pentester to find what this person already documented

  6. Anonymous

    When auth is enforced by JavaScript, every pentester becomes a growth hacker - and the bug bounty is a lifetime plan

  7. Anonymous

    Pro tip: if a single user can 10x your MAU, you didn’t find product-market fit - you found missing authorization middleware

  8. Anonymous

    Staging auth: so wide open, one curl loop earns you lifetime VIP faster than legit signups

  9. @deimossos 10mo

    Based developers

  10. @hur7m3 10mo

    Dev wants personal details to sue. Hecker attached malicious files to fuck with the dev.

    1. F 10mo

      why suing if the hack makes external stakeholders happy?

      1. @pooyabehravesh 10mo

        Fair enough

      2. @theodolu 10mo

        Money

      3. @JackOhSheetImSorry 10mo

        Not suing the hack. Multiplying users does

      4. @gmayv 10mo

        Because the hacker can now use this newfound knowledge to blackmail him for fraudulently deceiving his investors. This can go down in a number of ways now. It was a really stupid thing to do. I can only make sense of this as him trying to bait the dude into giving his identity so the company can royally fuck him

        1. dev_meme 10mo

          This was literally posted by simplehuman representative

          1. @gmayv 10mo

            They are all retarded then

  11. @Ilg4tto 10mo

    The best love story ever

  12. @deerspangle 10mo

    Oh I love that

  13. @AbolhasanAshori 10mo

    Rise with each other, not on top of each other. 🤝

  14. @hyena_stuff 10mo

    I've read enough yaoi to know where this is going

Use J and K for navigation