HackerOne expels mobile voting vendor Voatz from its security program over hostile interactions with researchers, the first time it's cut ties with an org
major kudos to HackerOne for taking a stand in support of security researchers. https://www.cyberscoop.com/... https://twitter.com/... Eric Mill / @konklone : True to form, @Voatz' statement deflects blame and misrepresents criticism, casting it as a few people with the a mistaken timetable. If Voatz actually believes this (which I doubt they do), then they are just not listening. Here are some reasons: 1/5 https://www.cyberscoop.com/... https://twitter.com/... Eric Geller / @ericgeller : The hits just keep coming for Voatz, which has struggled to offer coherent, factual answers to experts' questions. https://twitter.com/... John Panzer / @jpanzer : GOOD. (Very relevant in the context of all the discussions about how to hold our elections in the midst of distancing — whatever the solutions are, Voatz & companies that behave like Voatz should be shut out of them.) https://twitter.com/... Rob Pegoraro / @robpegoraro : Voatz—the startup that was going to solve absentee voting with a private-blockchain app—just got itself fired by the company hosting its bug-bounty program because its response to reports of vulnerabilities was to trash-talk security researchers. https://twitter.com/... Alex Stamos / @alexstamos : Good for HackerOne. https://twitter.com/... Sean Lyngaas / @snlyngaas : Scoop —> HackerOne kicks Voatz off its platform, citing the mobile voting company's hostile interactions with researchers. It's the first time in its 8-year existence that HackerOne has expelled a company from its security program: https://www.cyberscoop.com/... Greg Otto / @gregotto : SCOOP from @snlyngaas: HackerOne has booted mobile voting platform Voatz after multiple fights with researchers. First time HackerOne has removed a company from its platform in its history https://www.cyberscoop.com/... Kim Zetter / @kimzetter : Here's the report from @trailofbits (hired by Voatz to examine its app) that confirmed the MIT findings - “Our assessment confirmed the issues flagged in previous reports by MIT and others, discovered more”. https://blog.trailofbits.com/ ... Kim Zetter / @kimzetter : Voatz, for example, was hostile toward and critical of MIT researchers who found a number of security flaws with its mobile voting app - despite the fact that a security firm Voatz itself hired agreed with the MIT findings https://www.vice.com/... Kim Zetter / @kimzetter : HackerOne has booted Voatz, the mobile voting app firm, from its bug bounty program because of its hostile attitude toward security researchers. “We partner with orgs that prioritize acting in good faith towards the security researcher community...” https://www.cyberscoop.com/...
And HackerOne confirms it: they outright booted @Voatz, due to Voatz' poor treatment of security researchers. It's the right call, and the first time H1 has ever done this — major kudos to HackerOne for taking a stand in support of security researchers. https://www.cyberscoop.com…
True to form, @Voatz' statement deflects blame and misrepresents criticism, casting it as a few people with the a mistaken timetable. If Voatz actually believes this (which I doubt they do), then they are just not listening. Here are some reasons: 1/5 https://www.cyberscoop.com/.…
GOOD. (Very relevant in the context of all the discussions about how to hold our elections in the midst of distancing — whatever the solutions are, Voatz & companies that behave like Voatz should be shut out of them.) https://twitter.com/...
Voatz—the startup that was going to solve absentee voting with a private-blockchain app—just got itself fired by the company hosting its bug-bounty program because its response to reports of vulnerabilities was to trash-talk security researchers. https://twitter.com/...
Scoop —> HackerOne kicks Voatz off its platform, citing the mobile voting company's hostile interactions with researchers. It's the first time in its 8-year existence that HackerOne has expelled a company from its security program: https://www.cyberscoop.com/...
SCOOP from @snlyngaas: HackerOne has booted mobile voting platform Voatz after multiple fights with researchers. First time HackerOne has removed a company from its platform in its history https://www.cyberscoop.com/...
Here's the report from @trailofbits (hired by Voatz to examine its app) that confirmed the MIT findings - “Our assessment confirmed the issues flagged in previous reports by MIT and others, discovered more”. https://blog.trailofbits.com/ ...
Voatz, for example, was hostile toward and critical of MIT researchers who found a number of security flaws with its mobile voting app - despite the fact that a security firm Voatz itself hired agreed with the MIT findings https://www.vice.com/...
HackerOne has booted Voatz, the mobile voting app firm, from its bug bounty program because of its hostile attitude toward security researchers. “We partner with orgs that prioritize acting in good faith towards the security researcher community...” https://www.cyberscoop.com/...