Hacker News new | ask | show | jobs
by bongodongobob 742 days ago
It's not the definition of extortion. If I walk past a business and notice the locks on their windows are rusted and I happen to be a lock guy and say hey, I noticed your locks are fucked, I'd be happy to consult for you and show you how and why they are broken, that's just doing business. Extortion is telling them, hey, your locks are fucked and I'm telling everyone unless you pay me. It requires a threat.
2 comments

You just manufactured a completely different scenario.

The comment I responded to was this:

>it's only fair for them to financially award people that responsibly inform them of vulnerabilities instead of easily and anonymously selling those.

That comment includes the threat ("instead of easily and anonymously selling those").

So, yes. That is the definition of extortion.

I think preventing people from having that incentive vs an actual threat are not the same, which is how I read the hypothetical.
>I think preventing people from having that incentive vs an actual threat are not the same, which is how I read the hypothetical.

The following two sentences read the same to me:

"To remove my incentive to harm you, you should pay me".

"To remove my incentive to share information with others who may harm you, you should pay me".

And, the threat is pretty clear IMO.

Do you not lock your doors because you feel you shouldn't have to worry about people stealing your stuff because it's morally wrong to steal or do you do it to mitigate risk? Suggesting someone should mitigate potential risk is all we are talking about.
You're making a different argument now.

https://news.ycombinator.com/item?id=40577683

Great response, entirely agree.