Hacker News new | comments | show | ask | jobs | submit login

These people are doing work that typically warrants a six-figure salary or several hundred dollars per hour

He spent a day finding the exploit, and got $4500. That scales quite well if he can keep it up.

At the point the exploits are harder to find, Facebook can make a decision as to whether it's important to keep searching as hard, and raise or lower the price as they see fit. This is the market in action.

He might have made more on the black market, but why it would be worth more is important. On the black market, the transaction comes with legal risk. Risk increases payout (by reducing supply).

There would be very little legal risk associated with selling this on the black market. The problem would be finding the buyer. The prosecution would have to prove that the seller knew for a fact that he was selling the vulnerability to a known criminal.

Applications are open for YC Winter 2018

Guidelines | FAQ | Support | API | Security | Lists | Bookmarklet | DMCA | Apply to YC | Contact