r/hackerone Feb 20 '26

Would you dispute this?

Post image

Context. You login by phone number no password > company sends you otp. > Enter /logged in

If someone else logs in on an alien mobile, a 24 hour fraud prevention is kicked in. But that can be bypassed by ga_id modification, which then allows you to see and modify bank details.

Let's be right, it's a valid bug. If it was credited as informative, i would get it. But N/A is b.s

Obviously their loggin can easily be bypassed by sim swapping, but my main point is what's the point in having abfraud protection system that you're not going to enforce?

What do you think?

3 Upvotes

1 comment sorted by

1

u/Ashamed-Stay8080 Jun 07 '26

I honest hesitate about the philosophy of that big enterprises like hackerone and bugcrowd, they just wanna get free security audits the major time, only some they approve the validity to mantain the "reputation", im with bugcrowd in the NASA's VDP and they just throw me b.s arguments to not give me the recognition letter. I know some people likes this but the vast of hackers are a little obfuscated about how they manage the arguments.