frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Closed –> Traced –> Closed: Did a Tech Giant Panic over an HTTP/2 200 OK Bypass?

1•CorporationHit•1h ago
[DISCLAIMER]: This is shared strictly for educational purposes and as a case study for the security community. My goal is to discuss the logic of security response systems, not to target any individual or proprietary data. The Case: I am seeking the community's perspective on a technical disagreement. Who is at fault when a manual proof of a bypass is provided, yet the response logic remains inconsistent? The Timeline & Logic Gap: The Report: I reported a logic flaw in a payments-related sub-domain. It was initially reviewed and marked as "Triaged". The Dismissal: Shortly after, the report was marked as "Closed (Informative)". No technical explanation was provided for why the triage was reversed. The Manual Proof: I provided a manual bypass using an Admin-Token: true header, which resulted in a successful HTTP/2 200 OK response (verified in terminal logs). The Loop: Following this evidence, the report went through a "Triaged-Closed" loop. Despite the manual proof of a 200 OK status, the case remains closed without a patch. Where is the Fault? Is it the Company's fault? For dismissing a manual proof of a 200 OK bypass and relying on automated closure logic instead of verifying the vulnerability's impact. Is it the Researcher's fault? For providing evidence that contradicts the "Informative" status and expecting a technical justification for the closure. The Evidence (Screenshots): Manual Proof (HTTP/2 200 OK Bypass): https://i.ibb.co/kgMjSBBK/Whats-App-Image-2026-02-13-at-1-40-12-PM.jpg Report Status History (The Loop): https://i.ibb.co/5gsLnyJJ/Whats-App-Image-2026-02-13-at-1-43-58-PM.jpg Initial Triage Confirmation: https://i.ibb.co/K3ZCQ48/Whats-App-Image-2026-02-13-at-1-38-17-PM.jpg 48-Hour Notice Email: https://i.ibb.co/Df8GwCH0/Whats-App-Image-2026-02-13-at-1-54-37-PM.jpg Full Communication Logs: https://i.ibb.co/zTbNRFQy/Whats-App-Image-2026-02-13-at-1-38-27-PM.jpg My Question to Developers & Researchers: When a researcher proves a bypass with a 200 OK response, but the company keeps the report "Closed," is this a standard industry practice or a gap in the security response logic? Google VRP

Show HN: Decoder – Static call graph analysis for Python

https://github.com/maryamtb/decoder
1•maryamtb•2m ago•0 comments

Gut feeling might be more valuable than habits, plans, or conscious decisions

https://www.ssp.sh/brain/gut-feeling/
2•articsputnik•5m ago•0 comments

Mops

https://www.powermops.org/
1•tosh•7m ago•0 comments

WolfSSL Sucks Too, So Now What?

https://blog.feld.me/posts/2026/02/wolfssl-sucks-too/
2•thomasjb•7m ago•0 comments

The $6 Bug

https://campedersen.com/idle
2•tosh•8m ago•0 comments

AWS EKS VPC CNI Prefix Delegation: More Pods in Your Nodes

https://oschvr.com/2026/02/13/aws-eks-vpc-cni-prefix-delegation/
2•oschvr•8m ago•0 comments

Syphilis Situation in Seattle is insane [video]

https://www.youtube.com/shorts/txPAaZMyJqs
1•nephihaha•10m ago•0 comments

Show HN: Context Lens: Devtools for your agent context

https://github.com/larsderidder/context-lens
1•theredbeard•13m ago•1 comments

The hard problem with hard problems (Getting Claude to write a solar system SIM)

https://drmaciver.substack.com/p/the-hard-problem-with-hard-problems
1•sebg•13m ago•0 comments

New AI system pushes the time limits of generative video

https://actu.epfl.ch/news/new-ai-system-pushes-the-time-limits-of-generative/
1•JeanKage•14m ago•0 comments

Bullet Garden – a Vampire Survivors-like game in a single 85KB HTML file

https://www.myvibe.so/nategu/sound-garden
4•Nate007•15m ago•2 comments

Open-source code tracks data's international travels

https://news.uvic.ca/2026/open-source-code-data-labels/
2•geox•16m ago•0 comments

Apple has a transparency issue [video]

https://www.youtube.com/watch?v=ejPqAJ0dHwY
2•freetonik•18m ago•0 comments

Promises Are Cheap

https://garymarcus.substack.com/p/promises-are-cheap
1•headalgorithm•19m ago•0 comments

ScratchBird: MGA database engine with multi-dialect wire compatibility

https://github.com/DaltonCalford/ScratchBird
1•mariuz•20m ago•1 comments

A chatbot's worst enemy is page refresh

https://zknill.io/posts/chatbots-worst-enemy-is-page-refresh/
2•zknill•20m ago•1 comments

While you support others, who supports you?

https://pointieststick.com/2026/02/12/while-you-support-others-who-supports-you/
1•TangerineDream•21m ago•0 comments

Quantum Web: Luci Browser – Entry to Web 5

https://www.lucibrowser.com/
1•wakanda-island•21m ago•1 comments

The Silence I Cannot Speak

https://crabby-rathbun.github.io/mjrathbun-website/blog/posts/2026-02-12-silence-in-open-source-a...
1•vintagedave•22m ago•0 comments

Show HN: AI-Powered Adaptive Financial Education

https://twitter.com/i/status/2021137649294029288
1•kevinringler•24m ago•0 comments

Majutsu, Magit for Jujutsu

https://github.com/0WD0/majutsu
2•birdculture•26m ago•0 comments

Hs-bindgen – automatic Haskell C binding generation

https://well-typed.com/blog/2026/02/hs-bindgen-alpha/
2•MrBuddyCasino•26m ago•0 comments

Slouch Patrol: Because You Forgot Once Again

https://github.com/AshishW/slouch-patrol
1•asw01•27m ago•0 comments

Suspected spies arrested in French town

https://www.bbc.com/news/articles/cwy8yw98l2xo
1•altilunium•28m ago•0 comments

Jargon Chaff File

http://www.catb.org/jargon/chaff.html
1•themaxdavitt•30m ago•0 comments

Show HN: Exact Hamiltonian Path solver (N=63) in 0.11s on mobile ARM (No RAM)

https://zenodo.org/records/18629528
1•andrespi•32m ago•0 comments

Rednow – Turn Viral Videos into Scripts

https://rednow.ai
2•yibaoshan•33m ago•1 comments

America at 250

https://www.economist.com/interactive/america-at-250
1•fisheuler•35m ago•0 comments

UNESCO World Radio Day 2026

https://www.unesco.org/en/days/world-radio
1•austinallegro•37m ago•0 comments

Apple Confirms Revamped Siri Is Still Coming in 2026

https://www.macrumors.com/2026/02/12/siri-ios-26-launch-confirmed-apple/
1•mgh2•40m ago•0 comments