Hacker News new | past | comments | ask | show | jobs | submit login

Their bounty program[1] states:

> We may pay beyond the range at times when bugs are found to have significant risk.

If they don't consider this a significant risk, I'm not sure what is.

[1] https://www.paypal.com/webapps/mpp/security/reporting-securi...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: