Hacker News new | past | comments | ask | show | jobs | submit login

Is it just me or are these bounties really low. Unless I'm misunderstanding identification bypass could be incredibly damaging for the company and their customers, but it's only got a $3000 reward?

In my personal opinion you want to balance bounties against how much money that the person could receive using the exploits, vs the amount of trouble they could potentially get into.




It's insultingly low. Auth bypass is easily worth 5 or 6 figures if you can use it to transfer money.


You overestimate the value of these bugs to the black market. There is no shortage of hacked PayPal accounts for sale on the various dark net markets because the hard part is getting money off the accounts. PayPal will flag a transfer for a dozen different reasons. If you don't login to the hacked account from an IP close to the location of its owner; if you immediately attempt to transfer money off the account to a bank account; etc.


They're a "here's a token of thanks", not a "please don't sell it".


That's kinda hard to evaluate not having actually do it. That said, such a bug, if works as expected might be much more highly priced in the black market.


The dev posted in the comments that he received $10,000




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: