Hacker News new | ask | show | jobs
by 5h 3537 days ago
No, they would not be required - they are a private business and set their own terms.

As for being responsible - that is their motivation.

Should I assume that now you have access to this list that you will be contacting the site owners to notify them their sites are infected & exploitable? Would that be responsible on your part?