Hacker News new | ask | show | jobs
by chris_wot 3100 days ago
Irrelevant. If he found these bugs, even if he’s been a dick about it then he still found a bunch of vulnerabilities that Uber was exposed to. Pay the man, it’s a few thousand dollars as opposed to a major exploit!
2 comments

But that's my point. Of course he deserved a payout if he reported a previously unknown vulnerability. What I'm saying is that he (appears to have) behaved in such toxic way (sow) that someone denied something he deserved (reap). All parties in this are squishy humans with emotions.

No one looks good - he doesn't look good for how he behaved/communicationed, Uber doesn't look good for denying the payout on a valid report, and Hackerone doesn't look good for not enforcing a minimum payout on a valid report.

Just because you violate social mores does not entitle someone to violate the terms of their engagement with you.
A bunch of P5's that were rightly closed as informative. I completely agree w/ Uber's decisions here...