Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Really cool. I’ve done responsible disclosure in the past and finding someone who’ll listen is probably the hardest part of it


20 years ago emailing webmaster@, hostmaster@, abuse@ went direct to a tech person. I think these days it's also redirected to customer service.


IME sometimes you're lucky and it goes to a product manager, but then it is often put in the backlog with 100s other tasks.


Or just rejected—even postmaster@ which is mandated in RFC 5321.


Oh for sure, I'm sitting on a subdomain takeover at a pretty large company, I tried looking for an appropriate email or place to report it, found none so I just went the support route without any luck, just said they "will share it with the appropriate team", I've had control for over 2 months now.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: