| ▲ | john_strinlai an hour ago | |
>Do people normally report it or not? if you are reporting it for moral/ethical reasons, but are worried that the company will have a shitty response, report it anonymously to the company and any relevant regulatory bodies. but most companies, even without a bounty program, are happy to receive reports. a lack of a bounty program isn't really an indicator of how they will treat reporters, as most companies are ill-equipped to have a proper bounty program. otherwise, and i know this is an unpopular opinion here, but i'm a big advocate of just posting the exploit publicly when a company makes it hard/scary to report it to them. | ||
| ▲ | menomatter an hour ago | parent | next [-] | |
My issue was knowing that reporting would allow them to possibly discover my identity. Discovering the vul in itself may instead be considered unauthorized access. | ||
| ▲ | Computer0 an hour ago | parent | prev [-] | |
don't worry you are popular with me | ||