Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Do you have a source for that? Google's not giving me anything. I'd definitely like to know more - I can't help but wonder how widespread that kind of behavior is.



Locking security bugs from wide internal read access has been SOP everywhere I've worked for decades.


I think they're asking for a source on the specific claim about Microsoft employees selling bugs on the black market, which is what I would also like to see.

I don't need to be convinced that security bugs should be on a need-to-know basis during the responsible disclosure period, that seems obviously prudent. Anyone not working specifically on security can learn about the details at the same time as the wider public.


I don't know anything about that event, but it reminds of me when 20 Apple contractors had a scheme selling Apple user data for $7M.

https://www.nytimes.com/2017/06/09/business/china-apple-pers...


No source, but I'd be willing to bet it's very widespread.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: