Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I haven't used hackerone myself, so this is just based on limited observation, but it looks to me like it was automatically disclosed one month after the reporter made the request. Otherwise, I believe it would have said something like "schofield agreed to make this public".


That is correct. The reporter requested public disclosure after the report was closed. The bug automatically gets disclosed publicly 30 days after the report is closed, unless the team requests more time by re-opening the bug. You can read more about the disclosure philosophy here: https://hackerone.com/guidelines


Thanks for explaining that.

So maybe a feature-request for hackerone would be, don't auto-disclose on Fridays; instead bump to Monday. :)


Another interesting feature might be notifying the engineering team that a following list of bugs will be automatically disclosed in x days and give them a chance to review them with a fresh pair of eyes.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: