Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> You can report a self-XSS sev:hi (and bounty hunters do) and get many orgs to take them seriously, because they don't have serious security practices.

Which can be definitely high, if it can be triggered by giving specific URL, for example.

I think there is too much generalization happening here.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: