Hacker News new | past | comments | ask | show | jobs | submit login

Any new vulnerability will be sold to the highest bidder and/or exploited instead of being reported for the bug bounty because of this.



Most of the vulnerabilities I've disclosed, and I've seen disclosed, were disclosed for free, with no expectation of getting anything. Why do you think every researcher is an amoral penny pincher who will just sell exploits without caring for the consequences?


Wanting money to live = penny pinching. Very cool.


Projecting?


I know a lot of different people who do independent security research and have submitted vulns to bounty programs. Not a single one would even come close to saying "well, the bounty is low so I'll sell this on the black market."

Low bounties might mean that somebody doesn't bother to look at a product or doesn't bother to disclose beyond firing off an email or maybe even just publishes details on their blog on their own.

Bounties aren't really meant to compete with black markets. This is true even for the major tech companies that have large bounties.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: