Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The problem with such negotiation is that at the moment someone even describes the bug they have found, they eliminate the possibility of selling to anything other than the BB program. If you describe your bug to them, but then the BB negotiations go south and you walk away, you are a suspect in any future exploit of that bug. So the BB program knows that they have the researcher on the hook from the moment he makes contact.



What about publicly announcing it so anyone can make the exploit?


Or announce it publicly and then hack them yourself.


Also known as "commit multiple felonies."


I'd call it plausible deniability.


I'd also delete that comment, as it might harm any future legal defense.


On the web there is no delete!


fun thread




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: