So this wording is really interesting in the bug bounty sense and I’m curious if you know how it would be handled.
If someone hits an unsecured API, receives information, and notifies the company of this while also requesting a bounty, would that satisfy all of the requirements of prosecution?
The unlawful gain is the sticking point in my mind.