Chronotope’s avatarChronotope’s Twitter Archive—№ 137,553

      1. …in reply to @nandoodles
        nandoodles OpenWebHQ SecureWithHUMAN Bug bounties usually don't preclude the person or org claiming them from talking about the issue, they mostly just state a period after initial reporting that they ask people to withhold reporting on the issue so that they have time to fix it.
    1. …in reply to @Chronotope
      nandoodles OpenWebHQ SecureWithHUMAN Usually the folks who claim a bug bounty write all about it after giving the organization with the issue a deadline to resolve it, whether or not they do (and sometimes they don't)
  1. …in reply to @Chronotope
    nandoodles OpenWebHQ SecureWithHUMAN We've been talking a lot about independent auditing of ad tech & its ecosystem, but no one has really established good incentives to do so, it would be interesting to think thru how that might work. Perhaps the massively expensive certification folks should be made to throw in.


Search tweets' text