![Blaklis Profile](https://pbs.twimg.com/profile_images/1226847426641899522/9lxT8Zie_x96.jpg)
Blaklis
@Blaklis_
Followers
10K
Following
572
Statuses
3K
Infosec web frenglish speaking guy. CTF player with The Flat Network Society. Security researcher & bug bounty hunter.
Joined November 2017
RT @kevin_mizu: Thanks to the recent @PortSwigger top 10, I finally found the motivation to finish writing the 2nd article about DOMPurify…
0
14
0
This report illustrates a top problem for me, yes. The pressure that is put on both triage and mediation service by such things is causing a massive degradation of service, for everyone, and made triaging a painful experience. As for trying to guilt trip me; I'm spending (and I spent) a lot of my time to be helpful to "newbies", as you say. That doesn't change that I don't think it's a good idea to let them use a platform as a sandbox to learn. As in most fields : first, you're learning everything you need, then only, you're working. I don't see why it should be different for bug bounty, and why people consider it's ok to make people lose their time, and even more why people consider it's granted that its on others to educate them and fix their errors. Not to mention that responding to an issue saying there are other issues don't cancel that issue, whatever. This is a stupid reaction imo.
1
0
1
That's not like I'm advocating on how to defend your bugs all the time, to avoid that. I literally manage communities and talking about that, all the time. Once you get a few programs you're used to work with, that's something that doesn't happen very frequently. Not really a top problem to me. Platforms general issues are, however, a real deal to me.
1
0
1
They might - but I don't think the model is currently pushing for that and they'll probably just hit a wall instead, and I don't think either that's a good reason to let them lower the quality for everyone. Once again, this is a platform to connect professionals - and at some point, either you're restricting registrations, or you're applying sanctions to filter low quality stuff asap. Sanctions on repeated low quality stuff sent would both be reflected in the profile (rep loss, signal), and eventually to a temporary ban + giving a handful resources for the learning phase.
0
0
3
@midwestneil @CMD_0_0 I guess it's all platforms, and that's a marketing issue. Better present that you have hundred of thousand researchers instead of a few hundred skilled people?
2
0
2
@Masonhck3571 Not surprised, and a shame. Platforms should start fighting against that actively - applying sanctions (both applying the correct status, NA/Spam, instead of Informative + temp locking ppl and redirect them to learning platforms)
1
0
8
@CMD_0_0 If we want the field to grow, that's by not giving the impression everyone can do it. That asks for a deep learning phase that can't be avoided. Maybe it's not a good thing to let them hunt and hit a wall everytime - pretty sure that hurts them more than anything
0
0
2
RT @kevin_mizu: Such a pleasure to be part of the top 10! Thanks a lot to everyone who voted for my article. I hope to bring new and intere…
0
7
0
RT @PortSwiggerRes: The results are in! We're proud to announce the Top ten web hacking techniques of 2024!
0
267
0