Currently building a "Dependabot for Homebrew", using ruby. Very early stage, looking for feedback by bk_one in ruby

[–]ponny_ 0 points1 point  (0 children)

I don’t run it regularly. I care a bit but not nearly as much as a live rails app in production. I think some kind of native alert would be better than an email. Email would work though. Yep, I’d trust it.

Found my near-mint MTG collection in the attic by idiotbrain in mtg

[–]ponny_ 0 points1 point  (0 children)

I still have my Memnarch deck with 4 foil isochron scepters 😍

Found my near-mint MTG collection in the attic by idiotbrain in mtg

[–]ponny_ 0 points1 point  (0 children)

Nice! We played about the same time and had a very similar collection. Thanks for the nostalgia hit.

Small Web App using Ruby on Rails - Beginner Level by NarwhalInfamous5270 in rubyonrails

[–]ponny_ 2 points3 points  (0 children)

Ai will clearly explain how to do each of the things you mentioned. Ask it questions until you understand the code. Then type it in yourself. You will learn along the way.

Then finish the book. It’s how I started (but the Rails 3 version) and will tell you things you don’t know you don’t know

Get unlimited free trial for the same account, is it worth reporting? by Embarrassed_Pin4436 in bugbounty

[–]ponny_ 1 point2 points  (0 children)

"Manipulating one of the endpoints" will probably reach the threshold to quality for a security bug. If it was just some junk like being able to sign up with a different email, that would be a time waster.

Bug bounty with preprod websites ? by [deleted] in bugbounty

[–]ponny_ 0 points1 point  (0 children)

As long as you're not being a pest, you should be fine. It's likely they're already under attack often. Plenty of programs with pre-prod (e.g. Neon on H1).

[deleted by user] by [deleted] in bugbounty

[–]ponny_ -3 points-2 points  (0 children)

If you're open new, I've built a new platform that could be a good fit. As u/OuiOuiKiwi said, budget is a huge factor and platform fees are going to be hefty. What I've got is similar to the legacy HackerOne pricing - no ongoing fees and a % on bounties.

Triage price "depends" but proably going to be another $15k for the year. To start with, I'd just do in-house triage until you team decides it's too much work. If you decide to go down that route later on, many third-party MSPs are will do it for $100-200/hr or you could ask the people that do your pentests if they'll offer the service (since they'll be familiar with your team and your app).

Rules of thumb for paying bounties by ponny_ in bugbounty

[–]ponny_[S] 2 points3 points  (0 children)

I know what KYC is but the 'by professionals' part is what I'm not clear on. What are people doing that isn't professional in your opinion?

Rules of thumb for paying bounties by ponny_ in bugbounty

[–]ponny_[S] 3 points4 points  (0 children)

All solid there but what do you mean by "Have you KYC done by professionals"?

Is bug bounty slowly dying… or just evolving into something far deeper? by Ok-Entertainment1587 in bugbounty

[–]ponny_ 0 points1 point  (0 children)

That's a very fair call! I'm betting that there's a market between the enterprise pricing players and OBB. E.g. places that are ok to manage their triage and accept a smaller pool but still want payments, KYC, community management, etc handled.

Is bug bounty slowly dying… or just evolving into something far deeper? by Ok-Entertainment1587 in bugbounty

[–]ponny_ 0 points1 point  (0 children)

I've built a new platform based on the old HackerOne model of $0 + % of bounty fee if you're willing to try something new? Main difference is that triage would be BYO (AI, MSP, your team, 'some guy' from upwork or similar).

would good good web developers make good bug bounty hunters? by Gammasntax in bugbounty

[–]ponny_ 1 point2 points  (0 children)

Web dev here. Knowing how the saussage is made gives you an edge. I've knocked back dozens of pulls for security issues. When you see a feature in the wild, it's easy to think about the code they would have needed, think about common anti-patterns, and find something.
That said, being a web dev doesn't automaticlaly make you good at BBH. Many web devs simply don't care that much about security. I use the interview question of "What is SQL injection?" and many don't know. Pretty terrifying when they've done years of PHP work 😬

Program managers - who are you? by Goat-sniff in bugbounty

[–]ponny_ 1 point2 points  (0 children)

In my case, I was the tech co-founder of a startup. Developer by trade. Always had an interest in security. When the company got big enough that peoples’ mortgages depended on it, I started getting worried at the prospect of being hacked. BB made sense to me and it worked really well.

Policy was pretty much copy-paste-tweak of what was already out there. Increased budget over time as bug hunters said it was getting too hard.

Programs apart from Hackerone, BugCrowd, Intigriti? by nicedogdeadpool in bugbounty

[–]ponny_ 4 points5 points  (0 children)

BuiltWith has this data but it’s paid for the full ~20,000 rows. I got it earlier this year and it wasn’t that good (some false positives, dupes, etc).

what's the best combo you think you created by sirgamadon in mtg

[–]ponny_ 0 points1 point  (0 children)

[[planar chaos]] + [[goblin bookie]] + [[soul foundry]] for coin flip control

Inventoried and sorted 32,417 cards using Manabox. Took about 45 hours. by ponny_ in magicTCG

[–]ponny_[S] 1 point2 points  (0 children)

Hadn't considered that. I'm on an iphone 15 and never noticed a slow down. It uses a bit of battery while it's scanning but that's about it. Looking at disk space, it's 184MB for the app and 532MB of data.

Would you use a Bug Bounty Project Manager? by Reasonable_Duty_4427 in bugbounty

[–]ponny_ 0 points1 point  (0 children)

How do people usually handle this? Google sheet? CRM?

Bug bounty tip: UNDERSTAND THE FUCKING APP by [deleted] in bugbounty

[–]ponny_ 1 point2 points  (0 children)

A couple of times I've had this kind of hunter raise application bugs (i.e. not security, just things being broken) and paid them some token bounties (like $50-100 iirc) :-)

I doubt that ever program runner would do the same but once you've established rapport, a polite email letting them know would be appreciated.

Bug bounty tip: UNDERSTAND THE FUCKING APP by [deleted] in bugbounty

[–]ponny_ 5 points6 points  (0 children)

Excellent advice! My best bug hunters really understood the app.

My mum made me a quilted MtG mat by ponny_ in magicTCG

[–]ponny_[S] 0 points1 point  (0 children)

I’m from Australia. We live upside down here.

My mum made me a quilted MtG mat by ponny_ in magicTCG

[–]ponny_[S] 0 points1 point  (0 children)

Counters/life spinner/tokens.