Hacker News new | ask | show | jobs
by deadfece 1217 days ago
Maybe frame it as a regular bug in a legitimate use context? Lead them to their own discovery of the vulnerability, and they'll think they found it all on their own.

"Oh I used your sample API call but I keep getting out of memory errors." <your code has a bug in it that exposes the vulnerability itself>