Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Find out how much the vuln is worth in the black market, then ask Apple double that.

Well, because he is not a corporation, he will get jumped on by lawyers and will go to jail for blackmailing Apple.




Blackmailing? It's called negotiating from a strong position.


That really depends how will judge and lawyers look on it.


So now people that discover exploits should be bullied and threatened by corporations for asking for more money? Heck, I hope Apple does this so that no one will ever want to use them again.


I mean, that's the station where we are heading. The moment you will come to corporation and say: "I have this and this vulnerability, black market offers me X, I want 2X from you." Corporation will then subpoena you to get the knowledge from you and then cease and desist you to prevent you from spreading that knowledge further.

You will try to threaten that you will release it to black market if they won't pay you 2X? Yeah, that's blackmailing. So what else can you do? Either you will start blackmailing them (then I hope you know what you are doing) or you will outright sell it on black market and bypass communication to company altogether.


I would hope you wouldn't threaten that and just ask for more money. If your end goal is to do that, then hopefully you'll be security conscious enough to do so and say... hm, have no idea how that got there. Me personally... I'd release it to the public and watch as the corporation suffers until the next one where they'll be glad to pay more.


Or the words used in the negotiation.

"I feel the work done to discover this bug is worth $X"

vs

"You'll give me $X or I release it into the wild or sell it on the black market"


Yeah, let's be realistic. It will be either take the meager offer or we will subpoena it from you for free. Don't like it? Sucks to be you.


Oops, I was trying to install a used HDD and wanted to make sure it was clean with the forensic 7x write option, but I chose the wrong device from the CLI and wiped out the data you're too cheap to pay for




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: