Ranter
Join devRant
Do all the things like
++ or -- rants, post your own rants, comment on others' rants and build your customized dev avatar
Sign Up
Pipeless API
From the creators of devRant, Pipeless lets you power real-time personalized recommendations and activity feeds using a simple API
Learn More
Comments
-
Wait, whaaat?
If they wont give you 100% I would just spread black PR and give no fucks to be honest. -
@DubbaThony I worked for company X, found a bug/security issue in tool/framework Y in use and reported it, because that would allow RCE, they confirmed and released the bounty, now company X read the ticket and wanted a piece of the pie, because I "found it while working for them"...
-
@joas not trying, I already did, that's really a vile thing to even propose or have pass a fucking MEETING of people over that.
-
@JoshBent
Sigh... Okay, i missinterpreted that, but yeah, thats just plain greed. I have nothing more to say....
paraphrased
C: "hey, we've seen the ticket resolved with a bug bounty rewarded to you! congratulations!"
C: "we've talked about it today on our meeting and think we deserve 85% - since it was discovered by you while working on our contract and system!"
That was so bizarre to me and I was speechless for a good 10 minutes, didn't even have any witty reply afterwards.
I just cancelled the contract, reported the client to my middleman, explained it to the on-sight business contact and requested the final milestone to be released with one week notice until it gets to be a public case if not released through escrow.
I'm still somewhat shocked at how greedy one can be, the whole system package I was working on had estimated 150-300k post first week launch (tons of existing clients merged and unified into one system, with much more paid and feature stuff etc.), the bounty I got was around 3.5k, it still didn't sink in me.
rant