Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The smart thing to do, if a company has no public vulnerability bounty program, is to sell the information on the blackmarket instead. This will incentivize all companies to start their bounty program, whilst still getting some cash reward.


I don't know about the "sell the information on the blackmarket" part. But uninvited pen-testing seems pretty risky. Maybe it'd be prudent to have an ~anonymous pseudonym for this stuff.

And if you really care about reputation building, you could use an ~anonymous pseudonym plus the sha256 or sha512 hash of some string. If it all works out, you just share the string, and reap the credit.


I agree. No need to get way too unethical to make a buck.... Ask for Monero or something if they want the full disclosure before you publicly and anonymously do a full disclosure.


It might incentivize the companies to change, but it might not. Especially if you end up selling it to an entity who uses Meanwhile you are doing real damage.

Why not publish the leak online to force the company to fix it asap?




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: