- cross-posted to:
- [email protected]
- cross-posted to:
- [email protected]
Anyone finding a vulnerability now should really be submitting it to a broker instead of the company. Brokers pay way more for good exploits than the big guys (Google/MS/Amazon/etc) and won’t just refuse to pay claiming you found an undocumented feature.
I had a hunch going into the article and I was right.
I could have had some pity for those devs who are supporting the open source ethos being flooded with AI grifters spamming bug reports for the money. However that pity instantly goes right out the window given that they’re working for one of the biggest companies pushing AI and why tech hardware is becoming more and more out of reach for the average Joe.
I saw a PR to a project I follow that involves a specific piece if hardware. There are about 10 “solutions” in pr now of scammers trying to claim the bounty. None of them have even bothered to get the piece of hardware necessary to actually test their fixes. It’s disgusting.
I’m very happy for Claude starting to mark their code, and hope it becomes easier to detect. I’m actually all for ai being used to solve these issues, but I think it should make you ineligible to collect a bounty on it if you use AI.
Apparently Google doesn’t care about good PR anymore.
https://en.wikipedia.org/wiki/Don't_be_evil
Don’tBe Evil.
They have fully embraced it now.They’ve been on that track for a while. I find it insane that people still want to use their services. I degoogled many many years ago.
👍
Well this isn’t good
Hey, this is great. If Google wants their services to be less secure then so be it.
Services other people rely on




