Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>Ethical disclosure is a complicated topic, because researchers shouldn't hold bugs for ransom or demand high payment

Why not?

"Hey, I found a cvss 8.8 bug in chrome that allows arbitrary code execution when loading my http url. For X USD I can send a report along, and for Y USD I can send a commit with the fix."

Sounds like a basic contract to me

What I do think is ethically dubious is:

"Hey I found this bug and I will MAKE IT PUBLIC WITHIN 90 DAYS SO LOOK AT IT"

I know it's a convention from 'security researchers', but I think the first approach is more ethical than the latter.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: