Today's Most Popular
All Time Most Popular
Most Commented Articles
Top Rated Articles
Barracuda Networks Bug Bounty Program - Message Archiver 650 v3.2 Persistent Vulnerability BNSEC:703
5
Average: 5 (5 votes)
5
Average: 5 (1 vote)
5
Average: 5 (6 votes)
Recent comments
Editorial_Staff_Team
Teach51
Alejandra Tazewell
ZuTaMa
Timon
hmmm
While Wickr is wrong by not paying out the decalred bounty, the reasearchers behaviour is also questionable. From the time frame in the article it seems that the reasearch and bugs discovery work (2013-2014) was done prior to Wickr declaration of the bounty program(January 2014). Then, the question is would the researchers have disclosed the bugs to Wickr if it did not offer a reward? For me it seems that the researchers kept the vulnerabilities they discovered to themselves in hope that one day they could get the chance of making money out of them. While it is their right to get paid for the effort they made, the ethical thing would have been to disclose the vulnerabilities once they are discovered whether or not there was a bounty program. Everything has become a business...