• ITGuyLevi@programming.dev
    link
    fedilink
    English
    arrow-up
    24
    ·
    1 day ago

    Anyone finding a vulnerability now should really be submitting it to a broker instead of the company. Brokers pay way more for good exploits than the big guys (Google/MS/Amazon/etc) and won’t just refuse to pay claiming you found an undocumented feature.

  • smoothspoon@feddit.online
    link
    fedilink
    English
    arrow-up
    19
    ·
    2 days ago

    I had a hunch going into the article and I was right.

    I could have had some pity for those devs who are supporting the open source ethos being flooded with AI grifters spamming bug reports for the money. However that pity instantly goes right out the window given that they’re working for one of the biggest companies pushing AI and why tech hardware is becoming more and more out of reach for the average Joe.

    • Scrubbles@poptalk.scrubbles.tech
      link
      fedilink
      English
      arrow-up
      4
      ·
      1 day ago

      I saw a PR to a project I follow that involves a specific piece if hardware. There are about 10 “solutions” in pr now of scammers trying to claim the bounty. None of them have even bothered to get the piece of hardware necessary to actually test their fixes. It’s disgusting.

      I’m very happy for Claude starting to mark their code, and hope it becomes easier to detect. I’m actually all for ai being used to solve these issues, but I think it should make you ineligible to collect a bounty on it if you use AI.