Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Agreed. Paying security researchers fair rates is a good idea though right? Keeps future researchers honest?


Maybe. But as soon as they threaten to sell it to the baddies or use it for ransomware themselves, I would cease all communication and negotiation.

The legitimate threat the researcher has is to disclose to the general public. (And to disclose the next bug to the general public, if there's no good payment.)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: