Sadly you can't feed your children from media drama.
Maybe, in the long run, but it's more likely to get sued.
Sadly you can't feed your children from media drama.
Maybe, in the long run, but it's more likely to get sued.
By the way, if the problem is "how do I reliably get money from bug bounties" (as opposed to "I found a cool bug, what do I do with it") --
I strongly recommend finding a product with some kind of barrier to entry. Most researchers on these platforms are very low-effort. A gigantic, complicated product, like Workday, or even better a gigantic, complicated product that requires payment (!), like Slack for Enterprise, will usually not be getting very many reports. That product is hard to understand. But that means that -- once you've put in the effort to understand the product -- there's a lot more low-hanging fruit, and the company is likely to treat researchers better because of the lower report volume.
Suing someone for disclosing an actual bug is a long term losing proposition for any company in a competitive industry.
Request disclosure on hackerone then. Idk, breaking the law to get a job doesn't seem ok to me.
@cybernews' behavior in that thread isn't ideal, but they're more in the right than in the wrong on that one, judging by the screenshot.
At least Paypal was notified before the public disclosure!
Except for when you play their game, which means: submit bugs via h1 and only disclose if they allow.
So it seems like the real answer in these cases is selling the exploit on the "dark web". I mean why not? The vendor doesn't seem to care about security anyway.