|
|
|
|
|
by cookiecaper
3693 days ago
|
|
Don't expect a bug bounty program to protect you. I'm not a security researcher, but if I wanted to be one, I would do what I could to conduct that business pseudonymously instead of trusting that the company would stick to the representations made in the bug bounty program. Remember that the CFAA has both a civil and a criminal component; if the state decides to charge you, the opinion of the company whose computers you illegally accessed does not necessarily matter. JSTOR asked Carmen Ortiz to drop the charges against Aaron Swartz and she declined to do so. |
|