Following the advice of this post can make a 10x difference in outcome for founders. This is because they will sharpen their skill to raise this way in every round. The reduced dilution compounds. The additional money in each round can help get you to critical mass first. It’s a powerlaw. One of the most important things to understand when you’re doing a startup. Growth is what makes a company a startup: http://www.paulgraham.com/growth.html. Process and leverage in fundraising is an absolute condition to get there. This post should have 1000 points.
Yahoo has fully embraced working with security researchers. For a company their size (they're no. 1 in web traffic!) with that many different services, they're doing an amazing job. No company that size has ever moved this fast. Yes, they're catching up but they do it fast!
You make some very interesting observations. I'm pretty sure the folks at Twitter spend a LOT of time working on user engagement and solving the signal vs noise problem in recommendations etc. What's been their response so far when you reached out to them? I would try to reach out to the people trying to solve this problem (developers) instead of to management first, in case it's not a matter of decision making but a more of an algorithmic problem.
Well, if you have the email, just reply to it and re-open the conversation and see what happens. If you can explain it correctly, they might be able to research if the bug indeed existed and was fixed. I did a follow up on a bug that I submitted before the whitehat program was in place and that I never got a response on. They looked up the bug, replied to me and paid me. Very diligent.
I'm surprised at how many people just assume the FB sec team doesn't want to pay and therefore tries to not pay if they can get away with it. Their history of paying out is completely the opposite. I've reported several bugs and they're always extremely helpful. They're not an insurance company that wants to reduce cost by screwing over users and there is no historical evidence of that. They want to pay for bugs and get as many of them as possible. What they don't want is for researchers to mess with other users' data. The guy could have just used two accounts to demo (he managed to create a new account after his own account was blocked). Using Zucks account doesn't make it more convincing from a tech perspective. It only makes the guy taken less serious as most researchers care more about how it works than messing with accounts of famous people. Not the smartest move. I understand the sec team draws a line and doesn't pay researchers that mess with other people's data. That's not sleazy, that's sane otherwise it gets exponentially worse as people try to outdo each other in terms of impact instead of focusing on explaining the technique behind a hack.
The newspaper that published this, 'Telegraaf', is notorious for publishing bullshit. The article is very short, the journalist wouldn't be able to check if it's true, and the newspaper hungry to publish anything that attracts readers. Offline version of link-bait.
Ah, I see you did let them know and the vulnerability was fixed before you posted. Good. I recommend saying such a thing in your post because it helps people like me understand that you are in fact responsible about the disclosure.
Ryan, your post is NOT an example of responsible disclosure. You could have written your post and posted it AFTER alerting the Ice Box Pro guys and waiting until they had the main issues fixed. Your post would still be a good post. In fact, you seem to weigh the importance of your post getting on HackerNews above the security of the people who tried Ice Box Pro. The creators of Ice Box Pro had good intentions and messed up security (as almost any startup does to some extend). You are either ignorant to what security actually means or unethical, which at best is as bad as what the creators of Ice Box Pro did and maybe worse. Will you take responsibility if any of the users that tried Ice Box Pro get hacked as a consequence of your post?