i had a zoom call with people to discuss a major vulnerability i found.
Cool, for which website/app?
ooh i think i might know what it is
really?
i think we’re talking about different things, its when i logged into poprock’s account with a password, even though he had no password assigned.
uh thats bad.
i think you already fixed it
this sounds like a bug with your client rather than the server — as far as i can tell, i haven’t touched auth code in years
all i know is apparently i logged into an account with a password even though the account had no password assigned, and then you gave me a warning
that sounds more like the user configured their account wrong. right now its possible for someone to set their password to be blank (which is different from disabling password login).
you know jeffalo is serious when he starts using periods in his posts and replies
You should start documenting your bug bounties. A lot of people do
I agree with this, please do, will be an interesting read.
depression?