Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Agreed, although the reimbursement should be based on whether a reasonable person could consider that to be a vulnerability. Often it’s tricky for outsiders to tell whether a behaviour is expected or a vulnerability




Yeah, the reimbursement would need to be for a good-faith submission worth considering, even if it wasn't actionable.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: