Ask HN: How to deal with bug bounty hunters
Every few weeks I get an email that goes something like this:
Hi, I’m an ethical hacker and I found some security vulnerabilities in your site. Attached is proof.
I expect a reward for this information, can you let me know how much you will pay, or should I share this exploit online?
——— Now, none of the issues are very serious, nobody has been able to access data they shouldn’t have, they’re usually small things about header, XSS etc, but nevertheless valid.
I can’t really afford to pay them, and buy I also don’t want to suffer reputation loss.
At the same time, I don’t k ow that it’s realistic to have zero security recommendations as pretty much any project I’ve ever seen has some… although it’s a worthy target.
Any recommendations on how to deal with this?
1. Ignore them? 2. Pay them? 3. Thank them and ask them to move on
I usually fix the problem and to (3), but it’s concerning behaviour that seems to be increasing in frequency.