Hacker Newsnew | past | comments | ask | show | jobs | submitlogin



> Specifically, in multiple communications with MLB employees, STREIT claimed that he knew MLB reporters who were ‘interested in the story,’ and stated that it would be bad if the vulnerability were exposed and MLB was embarrassed.

Oh man, such a stupid thing to do. This turned a $150k bounty into extortion.


> Streit indicated his work was worth $150K but was also informed there was no ‘bug bounty’ program at the baseball league.

Sounds like a bug that would have been better off anonymously leaked for the other IPTV providers to pick up, after said bug was valued at 0 in greyhat dollars.


The bug couldn't have had less to do with streaming, and in the wrong hands would have been worth a significant amount of money—exponentially more than what the Shopify CVE calculator spit out and I replied with at the time. There's more here: https://prison.josh.mn/charges

There's a lot of nuance, and what was ultimately reported about the bug isn't how things played out—there's tons of context missing. I won't talk more of the bug, or the handling of situation. I realize it was the leading headline (more so than the "guy had streaming website") but it was, in my opinion, also the most far-fetched.


That is not what it says. They only said they had no bounty program to attract people to try and find bugs. That does not mean companies are not willing to compensate you if you find and report a bug in their system. I think 150k was well worth it, but the guy just worded it in the worst possible way.


The US sentences seem really crazy coming from Europe - like even violent rapists barely get 3 years here: https://www.gov.uk/government/news/sentence-increased-in-sex...


I don't know the details about this specific case, but to me "violent rapists barely get 3 years" is the crazy side. YMMV.


The US is a major outlier in sentencing for violent crimes and sex crimes. It's not the absolute peak in terms of sentencing, but its somewhere between the Latin American mean and the Middle Eastern mean, which is unexpected given its other human development indicators.


Your link does not back up your claim.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: