Facebook CSRF leading to full account takeover (fixed)
pyx.io
pyx.io
Also sounds like you should maybe try to move to a different country, if you can!
The "session" I found this bug in was around 2 hours long.
Because the system is complex, and security is hard.
Here's one. A use-after-free triggered due to some faulty logic.
Mistake? Yes. Amateur mistake? No. Even very experienced C/C++ programmers, such as Microsoft's top devs, may accidentally double-free, or use already-free memory.
They can't always catch everything, though.
It's certainly a mistake, but it was probably easy for developers and QA to miss.
I would disagree.
For a very actively developed web site, it takes very good focus to not trip up. Having a bounty program is an indication to me that they take security seriously. Fixing a security bug in a matter of hours indicates to me that they take security seriously.
Or would the effort not procure enough reward?