Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The author might as well have sold the exploits for the best offer.

If a company advertises a bug bounty problem but fails to follow through, such company kinda deserves to be hacked. I mean, you are wasting people's time and still getting critical bug reports, probably along with a detailed write-up.

Also, we might also discuss about the fact that for a company that moves (and earns) so much money as PayPal, 30 kUSD is probably very little when compared to the possible outcomes of being hacked.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: