Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I thought that the general issue was that they ignore the submissions and do not fix them - but the actual problem is that they give different severity and may not give fame or money? I think disclosure for those reasons is highly in gray area from ethical perspective. Regardless if it was clearly in the scope of the bug bounty program or not. That is distinct problem and does not justify public disclosure without warning with enough time.
 help



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: