Skip to content
This repository has been archived by the owner on Nov 16, 2022. It is now read-only.

Radar 46 #502

Closed
chadwhitacre opened this issue Feb 15, 2016 · 23 comments
Closed

Radar 46 #502

chadwhitacre opened this issue Feb 15, 2016 · 23 comments
Assignees

Comments

@chadwhitacre
Copy link
Contributor

What are you working on this week and why?

last week

@clone1018
Copy link
Contributor

Payday on Thursday!

@chadwhitacre
Copy link
Contributor Author

Roadmap (what?)

Short Term

Embarrassments:

Long Term

Color code:

  • red—external forces that we're under
  • yellow—administration
  • green—product development
  • orange—marketing
  • blue—capitalization

roadmap

@chadwhitacre
Copy link
Contributor Author

@clone1018 :-)

@chadwhitacre
Copy link
Contributor Author

Seems that we are getting more HackerOne traffic now that we offer bounties (#369).

@chadwhitacre
Copy link
Contributor Author

Most of the reports are low-quality and feel like a waste of time. :-(

@chadwhitacre
Copy link
Contributor Author

@hurlothrumbo has discovered the illustrator of the cover of The Internet (#462, #472).

windoweye

"Security"

An article for Computer Publishing Group discussed the different ways to keep the data on computers secure.

@chadwhitacre
Copy link
Contributor Author

Inbox 2, GitHub 2, L2 Support 1, Vendors, etc. 0.

Gosh, now we're getting low-quality security reports on [email protected], which we haven't seen since starting HackerOne (#255). Sup with that?

@chadwhitacre
Copy link
Contributor Author

Spent some time on grtp.co this morning (gratipay/grtp.co#115, gratipay/grtp.co#116). First French lesson in 20 minutes. Things on my mind after that:

@chadwhitacre
Copy link
Contributor Author

Just handed out our first "Not Applicable" on HackerOne (-5 reputation). Not sure how else to discourage junk reports.

@chadwhitacre
Copy link
Contributor Author

Aaaaaaand now we're looking at splitting Aspen out into a separate org: AspenWeb/pando.py#547. 👀

@chadwhitacre
Copy link
Contributor Author

@mattbk
Copy link
Contributor

mattbk commented Feb 17, 2016

L1 Support 0.

@chadwhitacre
Copy link
Contributor Author

Inbox 2, GitHub 3, L2 Support 0, Vendors, etc. 0.

Security 16.

@chadwhitacre
Copy link
Contributor Author

Hmmm ... merge commits are a little goofy coming from security (e.g.) since the PR numbers are off in the comment.

@rohitpaulk et al. Should we land security PRs via squash-and-rebase (as currently specified), or are we okay with merge commits? Merge commits are definitely easier under GitHub.

screen shot 2016-02-17 at 10 34 45 am

@chadwhitacre
Copy link
Contributor Author

Merge commits are definitely easier under GitHub.

And they're what we use otherwise.

@chadwhitacre
Copy link
Contributor Author

PR for merge commits for security: #505.

@mattbk mattbk mentioned this issue Feb 17, 2016
@chadwhitacre
Copy link
Contributor Author

Security 14.

@chadwhitacre
Copy link
Contributor Author

Inbox 3, GitHub 2, L2 Support 0, Vendors, etc. 0.

@chadwhitacre
Copy link
Contributor Author

Security 18!

@clone1018
Copy link
Contributor

@whit537 is this all just automated hackerone spam?

@chadwhitacre
Copy link
Contributor Author

No, it's not automated spam. HackerOne doesn't seem to have a listing of our publicly disclosed tickets, but all the ones so far are linked at #506 (comment). This is kind of annoying but ultimately I think it's really healthy for us. Most of this stuff is like shaving and brushing your teeth, but we've seen a couple more serious issues so far, and staying on top of the little stuff is good practice to prevent bigger stuff from cropping up.

@chadwhitacre
Copy link
Contributor Author

The email will be sent to the customer and will be logged as a ticket without triggering any notifications. Learn more.

Yesssssss! I've wanted this feature. !m @freshdesk

screen shot 2016-02-18 at 12 56 35 pm

cc: @mattbk

This was referenced Feb 18, 2016
@chadwhitacre
Copy link
Contributor Author

Email (what?)

screen shot 2016-02-23 at 3 47 27 pm

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

3 participants