RE: RE: SPS Governance Proposal - Pay Bug Bounty to louis88
You are viewing a single comment's thread from:

RE: SPS Governance Proposal - Pay Bug Bounty to louis88

Words
148
Reading
1 min
Listen
Play
4M

I voted against this pre-proposal for the following reasons:

  1. This is my main reason: louis88 publicly posted that there is an active vulnerability in a well-known Hive Platform before it was patched! This alone presents a major issue as it pretty much paints a target on the whole Hive ecosystem. He also dropped enough clues to encourage everyone to use AI to attack Splinterlands before the vulnerability is patched.
  2. I believe the bounty is excessive and sets prescedent for a $5,000 payment for every security bug in Splinterlands. Penetration tests usually start at $1,000 to $2,000, so at $5,000 there is a potential profit in hiring a pen test firm to find a bunch of vulnerabilities in Splinterlands then submit one after another for multiple payments of $5,000...

Here is the screenshot from his post that gives away some clues and has been up for a month now:

@seattlea: I voted against | Ecency