Complaining that the finder poked around too much while asserting that he had access to very little.
Complaining that the finder poked around too much while asserting that he had access to very little.
https://www.google.com/about/appsecurity/reward-program/#rep...
Sometimes that's not easy but slurping tons of data to demonstrate the scope of the vulnerability is rarely necessary from a technical perspective. That said, if your report is being ignored it becomes a very tempting avenue to get priority.
We also provide a test account upon which researchers can use if they wish to attempt to modify or read private information. They should stick to that data and I'd encourage other bug bounty programs to do similar.
In my eyes this researcher should've stopped as soon as they started seeing private data and reported it, it sounds as though they continued to read private information well after they realized it was private data they were viewing.
I realize not every bug bounty program plays fair. We look specifically at our bug bounty triage team (via the platform we use) to make sure we are treating researchers fairly and that researchers are obeying the agreed upon rules. They're the neutral third party in our eyes. They keep us honest and researchers honest. At least that's how I approach it all.