I feel this post. I still have an open bug where the policy states “please send us an email if you don’t have PGP to encrypt your report and we will respond with a secure way to send your reports”
Never heard back. Bug still exists. I’m just far less inclined than JR to follow up and spend my free time on this.
If you want to play security theatre be my guest, not my job to entertain this.
chaos.social
Stefan Eissing (@icing@chaos.social)
Joshua Rogers on his bug bounty experiences in 2025.
Positive for #curl, kafka-esque for all others mentioned. ‚BugCrowd‘ seems to a typical l...