5 ms·
Yeah I reported a j-frog vulnerability to Anthropic. It was downgraded to “informative” and they asked me to prove that I could exfiltrate data. I replied that
by nextzck 1mo ago
Yeah I reported a j-frog vulnerability to Anthropic. It was downgraded to “informative” and they asked me to prove that I could exfiltrate data. I replied that exfiltrating data is against their program’s safe harbor policy and they just never responded. 2 months later the claude code source code leaked.
- inigyou 1mo agoHacking someone who asks you to hack them is legally safe even if not written in their default policy
- apimade 1mo agoIn my experience, program requirements are mostly there for the lawyers. If you act in good faith, communicate clearly, and conduct yourself reasonably, most companies will work with you — even when you've technically wandered outside the neat boundaries of their risk-appropriate, regulatory-reviewed policy. That isn't protection, of course. Eventually you'll encounter a bounty program run primarily by lawyers, procurement, or someone optimising a graph trend-line. And we know what tends to happen next. Those programs, and organisations, develop reputations. Researchers talk. Companies get discussed at conferences, in private groups and across the community, and some become informally blacklisted. Microsoft is a useful recent example: researchers have publicly walked away from five-figure bounties to make a point. There are excellent people working there, but organisationally Microsoft has repeatedly struggled to engage with the security community in a way that feels collaborative, rather than adversarial. Unless you're one of their paid partners, intermingled in their ecosystem. A lot of that seems to come down to incentives: somebody, somewhere, wants the numbers to look better. That doesn't work particularly well in an industry that, like most industries, ultimately runs on relationships, trust and specialisation. If a company marks something critical as informational, sometimes the most effective response is a CVSS parameter argument. It's a snarky comment: "Okay — so if I find a way to abuse your own infrastructure to message your customers, trigger a major incident and create regulatory problems for your clients, you'd prefer I treat that as informational too, and instead just report it to regulators?" Surprisingly often, that gets the issue reconsidered. Have you annoyed an analyst? Maybe. Does it matter? Probably not. Neither of you will remember the exchange a week later, but you might have corrected a bad risk decision on their side and you'll see a positive outcome on your side. Mistakes happen. I generally advise companies and hackers alike to follow Kiwicon's #1 rule.