Hacker News new | past | comments | ask | show | jobs | submit login

If you report a bug to a company that has no posted bug-bounty policy, you really shouldn't be expecting anything but a "thank you". If you don't get a thank you, then you have a right to be nonplussed. Anything beyond a thank you (cash, T-shirts, warm hugs) is pure gravy and, IMHO, ought to be appreciated as such.

That said, yes, big companies really ought to have official bug bounties. But that doesn't mean you have a right to expect them.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: