Hacker News new | ask | show | jobs
by colechristensen 3973 days ago
If this was an essential security library instead of a fun website, this would have been an incredibly irresponsible disclosures.

Bug bounty programs searching for security vulnerabilities rarely need completed proof of concept exploits – crashes are enough. You've laid down all of the pieces for someone competent to potentially do some real damage without much work at all, and that's exactly why the request was made not to disclose any further vulnerabilities.