Wholesome Hacker-Founder Exchange: Exploit Disclosed, Lifetime Membership Offered
Description
A screenshot of an email exchange between Phalgun from Simplehuman ([email protected]) and a user named Blake. Phalgun writes that he knows Blake found a way to bypass the subscription system, is impressed, and offers a lifetime membership in exchange for disclosure of the hack and stopping the bypass. Blake responds graciously, accepts the offer, agrees to share the technical details, and even discloses a second vulnerability as a show of good faith. The exchange includes a 'SORRY' sticker with a cute character. This is a heartwarming example of responsible disclosure handled respectfully by both parties
Comments
21Comment deleted
The best penetration test is the one where the founder emails you saying 'I'm not even mad, that's impressive' and hands you a lifetime license
Most companies send a C&D letter when you find an exploit. This one offered a lifetime subscription. It's the bug bounty equivalent of getting equity instead of a restraining order
Finally, a growth-hack that literally hacks growth metrics - good thing legal signed off with a lifetime coupon instead of a cease-and-desist
The rare moment when a company's bug bounty program is just 'please stop breaking our stuff and we'll give you free access' - essentially paying the ransomware in product licenses instead of Bitcoin
When your analytics show 10x user growth but it's actually one engineer with a subscription bypass and a for-loop - the SaaS equivalent of discovering your 'viral growth' was a single determined developer who really didn't want to pay $9.99/month. Props to both parties here: one for the creative session management exploit, the other for turning a potential PR nightmare into a teaching moment. This is what 'responsible disclosure' looks like when both sides have actually shipped production code - mutual respect, technical curiosity, and the understanding that today's vulnerability researcher might be tomorrow's security engineer. Plus, offering a lifetime membership is cheaper than hiring a pentester to find what this person already documented
When auth is enforced by JavaScript, every pentester becomes a growth hacker - and the bug bounty is a lifetime plan
Pro tip: if a single user can 10x your MAU, you didn’t find product-market fit - you found missing authorization middleware
Staging auth: so wide open, one curl loop earns you lifetime VIP faster than legit signups
Based developers Comment deleted
Dev wants personal details to sue. Hecker attached malicious files to fuck with the dev. Comment deleted
why suing if the hack makes external stakeholders happy? Comment deleted
Fair enough Comment deleted
Money Comment deleted
Not suing the hack. Multiplying users does Comment deleted
Because the hacker can now use this newfound knowledge to blackmail him for fraudulently deceiving his investors. This can go down in a number of ways now. It was a really stupid thing to do. I can only make sense of this as him trying to bait the dude into giving his identity so the company can royally fuck him Comment deleted
This was literally posted by simplehuman representative Comment deleted
They are all retarded then Comment deleted
The best love story ever Comment deleted
Oh I love that Comment deleted
Rise with each other, not on top of each other. 🤝 Comment deleted
I've read enough yaoi to know where this is going Comment deleted