Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Then why the immediate escalation?

Wouldn't it have made more sense to contact the researcher directly, rather than using his position of power to pressure the researcher's company's CEO?

Why not assume good faith? (Which is what I would think a white hat bug bounty program should assume)



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: