Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yep, you should really give up significant income from companies that do responsible vulnerability disclosure in the name of a random HN's commenter's values.


At no point did I say you should give up income.


"Always just publish your research."

In most bug bounty programs I've seen (including Apple's and Facebook's) payouts are contingent on not publishing the research without consent.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: