New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Comments
Don't lose hope
Any Singapore vps deal?
Bring back the Singapore VPS deal and I'll grab an annual ONI-3
Anyone notice a new location pop up this evening?
Perth, Darwin when
Must have missed the turnoff to Canberra when going south on the highway. Easy mistake I guess.
Big thanks to @oloke for the continued support
Whoaaa. Melbourne???
Premium support from vampires.
soon™️
Crikey, must be the NBN mucking things up
@onidel any plans to bring S3 to Amsterdam?
Hello I want to order 250GB of oloke.
Please continue. Payment in oscypek only.
Whenever you hear someone talk about continuous improvement, pay attention to their project, because that concept can work wonders over time.
Any plans for pay for actual usage (per gb) with prepaid credits like Bunny.net? Looking for a Bunny.net alternative for S3 storage but don't want to commit yearly for a fixed size.
We've just released a new platform update, introducing SSO support with Google, GitHub, and passkeys, along with a range of UI/UX and security improvements.
Hi @onidel
Very lovely the new touring function on the Cloud Dashboard, but can we have a skip button for it, it's 34 steps and I don't think I can skip any of those T_T
done
yep I spent ~90 seconds going through all the touring yesterday
CHAMP 🫡
we should reward you with Onidel expert badge
We launched a public Bug Bounty Program for security researchers and ethical hackers to help us keep our platform secure through responsible disclosure.
We offer rewards up to $500.
You can read more about the rules and scope of the program here:
https://kb.onidel.com/hc/kb/articles/1775831946-bug-bounty-program
Once your submission gets accepted, you will also be listed on our Hall of Fame page
According to the rules:
Often, a potentially exploitable bug may be found but determining whether it really is exploitable can take a while. So does this 48 hour period start from the time the bug was discovered or from the time its exploitability was determined?
Even if it was succinct and came with a trivial reproducer? It might be better to just say that it'll be ineligible for the bounty rather than saying it'll be rejected (i.e. not fixed) outright. After all, surely you wouldn't refuse to fix a reported and trivially reproducible vulnerability just because an AI generated the report, right? You'd just not consider it eligible for the bounty?
Also, what would RCE leading to non-elevated privileges be classified as? For example, what would compromising a QEMU process and gaining full code execution on the node, but still confined to the QEMU user and not root (you do run QEMU as an unprivileged user with sandboxing enabled I hope!) count as?
A bug bounty program is an awesome idea btw! Congrats on setting one up!
Right, here we meant from the time it was confirmed to be exploitable.
I'll add a clarification to the rules as well.
that is just an example of what we consider a critical issue. Compromising QEMU and achieving code execution within the QEMU process context would generally fall somewhere between High and Critical. If the compromise does not result in root privileges, the severity ultimately depends on what can actually be achieved and the real-world impact (there are other defense-in-depth layers)
that said, if the vulnerability is in QEMU itself rather than in our own services or infrastructure, it would not be eligible for a reward as it is considered a third-party issue. If there is a patch and we are still vulnerable after 90 days then it will be eligible (not saying we would wait that long to patch such a critical issue)
Might want to mention that the 90 day countdown starts from when a patch is created, since the current text only mentions the disclosure of the vulnerability in public. Anyway QEMU was just an example, I was just curious. :P
I figure the intent is to avoid AI slop reports. I'm just a nitpicker for language so the phrase "rejected outright" caught my attention. I doubt they'd actually refuse to fix a severe reported vulnerability in any situation, even if the reporter made themselves ineligible for the bounty.