Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Btw, your HN search result page links to all of the references that you THINK what the term "Responsible disclosure" means. Be it "coordinated disclosure" or whatever else, I don't care. But I don't think it's ethical to disclosure the security vulnerabilities to the wild without contacting the vendor and given them a timeline (should be MUCH LONGER than 24 hours) and the benefit of doubt first.

Hypothetically speaking, if you are researching vulnerabilities solely for the intent of money (because you can sell to them to 3rd parties or your side hedge fund business can profit from disclosures in the stock market) then shame on you, because you are doing the society a dis-service and gaining on everyone' losses. To me, you are as evil as those hacker who utilize them.



There's a decent counterargument - take it or leave it - that this kind of research is extremely difficult and expensive, and upon success, privately weaponizing it and/or selling it to organized crime or nation state-level actors is extremely attractive, and therefore, the ability to short the stock of a sloppy/insufficiently-careful HW vendor to fully or partially fund the research instead is legitimate in that it ultimately improves overall-societal welfare relative to those other alternatives.

Vendors who wish to discourage that behavior could offer comparably-large bug bounties instead. And, of course, make their products more secure in the first place.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: