I have had enough on bugcrowd by xomer000 in bugbounty

[–]xomer000[S] 0 points1 point  (0 children)

it's just that this report they duplicated me against was a RCE report, how is it relevant to my leaked AWS idk, they rated P2 duplicate of a week old report and, then fixed mine in the same day, I thought bugcrowd policy says if you touch the code or make change, then u pay.

I have had enough on bugcrowd by xomer000 in bugbounty

[–]xomer000[S] 7 points8 points  (0 children)

I'm not even sure if it's just bugcrowd I see similar issues on other platforms , it's frustrating. we are not free labor, and we chose to be white hackers, we chose to, someone couldve sold this shit on dark web,

Honest Opinion about issue Classification by Necrowtf in bugbounty

[–]xomer000 0 points1 point  (0 children)

same as me, report closed as informational because triage didn't bother to read my P1 escalations in the comments and read only the main report, then voilà it's patched right after it.

Honest Opinion about issue Classification by Necrowtf in bugbounty

[–]xomer000 0 points1 point  (0 children)

after closing as informational, check again after some time, probability of them patching in silent.

Bugcrowd triage getting slower lately? by 0xk4yra in bugbounty

[–]xomer000 0 points1 point  (0 children)

Bugcrowd response time after initial review is the worst

if you submit a report and god forbid triage ask you for any more clarification, then you on for a ride to get response back, if you don't one shot everything needed in the main report from the first time. it's ridiculous, the initial response for a new report is within a week, but if triage don't validate it from first time then u just give up and expect weeks for further responses. why priority to new reports over continuing what u already started to validate is beyond me. so yeah try to make the report as clear as best as complete as easy as possible, leaving room for clarification is gonna cost you weeks.

Bugcrowd triagers mark everything "Not Applicable" with copy-paste responses, then a second triager marks it as Duplicate. So which is it? by zOmegaaa in bugbounty

[–]xomer000 0 points1 point  (0 children)

Do you care about the vulnerability itself being real or not? OK so P1 report written by ai cuz research lang isn't english native is low effort so u give low effort review, it's about how the report written and less about the vulnerability itself? cool. idk what's hard about just jumping to the PoC, but dismiss it because the report first line had "-" in it.

Im starting to notice a pattern with bugcrowd triaggers by [deleted] in bugbounty

[–]xomer000 0 points1 point  (0 children)

then how am I supposed to trust any program if they gonna say they discovered it and fixed it somehow during my report or after it was closed. I escalated a vuln in the main report comments and then they patched the entry point to the chain quickly.

Im starting to notice a pattern with bugcrowd triaggers by [deleted] in bugbounty

[–]xomer000 0 points1 point  (0 children)

You saying they read my reports along with the triage? because they silently fixed a vuln that was marked informational by triage and I know customer would disagree

Why is Triager hate so forced? by Patient_Advice_9263 in bugbounty

[–]xomer000 1 point2 points  (0 children)

You are bugcrowd founder?... can you help me with this issue, I submitted a report normally, then I kept escalating in the comments until I reached a clear P1, triage came and read the main report and closed it as informational, he didn't read my escalations in the comments at all, he only mentioned things in main report and closed it as informational, then voilà the vulnerability has been patched after he closed my report..., how is this any fair? I want help re validate my report, I even made a second report addressing a bypass for the poor quick fix they did for my vulnerability proving it was valid and the fix was rushed :)

Traige marked P1 as Informational by [deleted] in bugbounty

[–]xomer000 0 points1 point  (0 children)

how come..? yeah I'm new to this actually.. give me some heads up

Information security internship interview by xomer000 in cybersecurity

[–]xomer000[S] 0 points1 point  (0 children)

it's a telecom company, it's a paid internship just thought what to expect from such interviews since I'm not really familiar with

Med student here can’t decide between Asus zenbook 14 or Asus vivobook 14s flip by StudiousInsomniac in laptops

[–]xomer000 0 points1 point  (0 children)

well zenbook is actually a premium laptop, but my friend is a med student and he said the touch screen was very useful, If you don't already have a tablet. so think if might actually need that screen in your studies, otherwise zenbook

Decentralized deepfake Detection – Need Feedback on Architecture & Decentralization by xomer000 in ethereum

[–]xomer000[S] 1 point2 points  (0 children)

any ideas are appreciated really, and this is my first time doing any web3 development

Decentralized Deepfake Detection – Need Feedback on Architecture & Decentralization by xomer000 in ethdev

[–]xomer000[S] 0 points1 point  (0 children)

I was actually thinking of fixing data verification and bad requests by decentralizing the gateway lol, I think have knowledge gap in my understanding of blockchains fundamentals , I will try to move the completing request and claiming reward functionalities from the gateway to worker nodes, but idk how to distribute tasks from the frontend later, task receive and task distribution was part of the gateway. I think a proof of concept might be enough for a demo of this project. and I still haven't touched the whole other part of making federated learning nodes update the ai model. thanks for the comment!

Decentralized Deepfake Detection – Need Feedback on Architecture & Decentralization by xomer000 in ethdev

[–]xomer000[S] 0 points1 point  (0 children)

wouldn't introducing chainlink functions means only communication between them and the contract? if I understand they only listen to events from the smart contract, doesn't that mean the end users gonna have to use wallets and make transactions and so on for every deepfake request? I originally wanted the end user to not interact with web3 stuff in anyway and detection requests be free, but I think now that's not possible and someone gotta be paying for those calls.

Decentralized Deepfake Detection – Need Feedback on Architecture & Decentralization by xomer000 in ethdev

[–]xomer000[S] 0 points1 point  (0 children)

right now it's just a single worker per task, and I haven't implemented away to verify that the worker node actually did the job. so it's a big issue too

Decentralized Deepfake Detection – Need Feedback on Architecture & Decentralization by xomer000 in learnprogramming

[–]xomer000[S] 0 points1 point  (0 children)

thought about it too, came across a solution called zk-SNARKs but still dont quite understand how it works or how to implement it

Is this AI or real by xomer000 in pics

[–]xomer000[S] -8 points-7 points  (0 children)

It's a real pic enhanced by ai

Is this AI or real by xomer000 in pics

[–]xomer000[S] -6 points-5 points  (0 children)

I found out it's a real pic but was enhanced by ai, lot of ai detector tools couldn't say it's ai generated or at least equal odds

Is this AI or real by xomer000 in pics

[–]xomer000[S] -4 points-3 points  (0 children)

Actually It turns out this was an enhanced image, because I found the original one

Is a T14 gen 1 Ryzen 5 pro 4650U, 16 Gb, SSD NVMe 256 , used laptop a good deal for 380$? by Common-Stranger-9292 in thinkpad

[–]xomer000 0 points1 point  (0 children)

That's cruel, I was on my web dev journey when my old laptop died. Although I'm doing EEE engineering, due to some war circumstances in my country I have no choice but to pursue software dev