Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Actual legal threats are uncommon but I have seen some companies try to offer a bribe disguised as a retroactive bug bounty program, in exchange for not publishing. Obviously it is important to decline that.


Decline because it'd mean you were profiting off of a crime? Or that the opportunity of publishing has higher value than the bribe?


Decline because the public deserves to know the company has that approach to security.


Take the Money and have someone else publish it


Thanks, its cool to hear attitudes have changed.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: