If you find a potential security hole, you should contact devs and wait for an explanation or patch before making it public.
You are viewing a single comment's thread from:
If you find a potential security hole, you should contact devs and wait for an explanation or patch before making it public.
I completely agree. If this is a legitimate exploit, giving it publicity before contacting devs or the project is reckless and puts the network at a greater risk. It's called responsible disclosure, look it up.
It isnt that bad, even if it were to be exploited malicious attackers would compete with each other and achieve their daily task limit whitout gaining any credit, and then getting banned from the project.
Edit: I forgot - The main problem is people accidentally feeding bad data to the project