Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If they have a billion dollar valuation, this fairly basic (and irresponsible) vulnerability could have cost them a billion dollars. If someone with malice had been in your shoes, in that industry, this probably wouldn't have been recoverable. Imagine a firm's entire client communications and discovery posted online.

They should have given you some money.





Exactly.

They could have sold this to a ransomare group or affiliate for 5-6 figures and then the ransomware group could have exfil'd the data and attempted to extort the company for millions.

Then if they didnt pay and the ransomware group leaked the info to the public, they'd likely have to spend millions on lawsuits and fines anyways.

They should have paid this dude 5-6 figures for this find. It's scenarios like this that lead people to sell these vulns on the gray/black market instead of traditional bug bounty whitehat routes.


They should have given him a LOT of money.

Would you settle for a LOT of free AI generated legal advice? ;)

Who says they didn't give him money?

I reckon he would've mentioned it if he got a bounty, 100% deserves the bag



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: