Ask HN: How do you investigate server-side bugs that affect subset of users?

  • Posted 9 hours ago by jatin-dot-py
  • 1 points
I’m looking for engineering perspectives on a problem I encountered while disclosing a historical server-side authorization issue.

The behavior: - Only affected a subset of private accounts - Vendor test accounts were not vulnerable - Reproduction depended on account characteristics , unknown internal account flags - The behavior disappeared mid-investigation (likely due to a server-side change)

The report was ultimately closed as “not reproducible,” despite evidence earlier in the investigation.

My question: how do you validate, root-cause, and confidently close authorization bugs that are conditional, subset-only, and vanish during triage?

What does good disclosure handling look like in cases like this?

1 comments

    Loading..