Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Ah, just realized you're the OP. I don't think there's anything particularly irresponsible about posting an already-public disclosure to HN or other aggregators. It's the first person posting it publicly without first privately disclosing that I find irresponsible.


May I ask for your opinion on the $500 bounty issue that was mentioned?


from http://news.ycombinator.com/item?id=3321366:

> I think having a bug bounty program is actually a lot better than the vast majority of sites / vendors that don't even have a whitehat [aka responsible] disclosure program, let alone a bug bounty program. It's worth noting that this is just the base bounty - I've seen us pay out a lot more for good discoveries. $500 is also the base that Google and Mozilla offer for their programs (http://googleonlinesecurity.blogspot.com/2010/11/rewarding-w..., http://www.mozilla.org/security/bug-bounty.html). What would be a good price, do you think? I'm not hooked in enough to know what black market prices are like for bugs like this.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: