Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Depending on what a black hat could do with the data in your database, it might absolutely be worth it. I understand that 350k is way more than bug bounties usually pay, but 3.5k is taking advantage of people's ethics to outsource your security.

Let's put it another way: The team who discovered this has skills WELL worth 350k for a year's worth a work. How many security issues would they have to catch for it to be "worth it"? Maybe more than 1, but 100 show stopping vulnerabilities for 350k is crazy to me.

edit: ESPECIALLY slack, if it was possible to use this to get access to any chat logs.



No, none of this is how vulnerability research compensation works.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: