Yahoo, please start with a Vulnerability Reward Program
nilsjuenemann.de
nilsjuenemann.de
As much as I support these kinds of programs (https://nealpoole.com/blog/responsible-disclosure-programs/), that's a false dichotomy. Some companies have responsible disclosure policies or vulnerability reward programs. Some companies don't.
Anecdotally, the companies that do have programs don't inherently respond more quickly or handle reports better (ie: https://nealpoole.com/blog/2013/04/experiences-with-the-yand..., https://nealpoole.com/blog/2013/03/csrf-persistent-xss-in-my...). In contrast, companies that don't have programs may still be very responsive and willing to work with researchers; I reported issues to GitHub, Etsy, and Facebook before their respective programs were in place and they always responded quickly and effectively.
It comes down to the people who focus on security at the company and the way in which security is prioritized. If your company doesn't value and prioritize security, a responsible disclosure program won't make anyone's life easier.
In that sense, I do think that companies can and should do a better job of working with security researchers, regardless of whether they have a responsible disclosure program or vulnerability reward program in place. If a company takes security seriously, it should make it easy for researchers to report vulnerabilities. Researchers shouldn't feel that their reports are being sent into a black hole: if they do, they'll be less likely to spend their time reporting issues in the future.
PS: I'm an ex-paranoid. things might have changed since I left, but I'm pretty sure they'll still listen to reports.
Now a lot of the major players have policies promising no legal action for responsible disclosure, some even have rewards (whether monetary or acknowledgement) for the hackers.
In this case, a response was given, no legal action was threatened, and the bug was quickly fixed. Isn't this the goal? Looks like Yahoo is doing their job here.
It's in Yahoo!'s incentive to provide whitehats incentive, because people with malicious intent already have incentive and Yahoo! should want legitimate security research types to find vulnerabilities before attackers do.
Trouble is, it's not necessarily in the company's interest to acknowledge a past vulnerability in writing. Security team could've called him though; no paper trail, and it would've felt very authentic and personal.
I agree with Nils that talking to bots sucks! These are big issues, and it feels lame if you don't think the issue is being given the attention it deserves (even if that attention is directed at you).
[edit]: grammar
as per me there should be some beginning to make atleast world's top 10,000 site hack proof ? what you guys have to say here...
Somebody is not doing their job right.
I've gotten in trouble for finding loopholes in some reputable companies' setups, HAD I KNOWN that vulnerability rewards existed (I only found out recently)...my hat would've never been black. My ignorance is laughable, because I've never really been in the hacker scene...just look at my handle (quacker). BTW: time to start emailing companies :)
Title Suggestion: Yahoo - pay hackers for errors
Just like quite a few insider trading cases it's the wife/family members that get the tip and buy the shares.