Hacker News new | ask | show | jobs
by tsimionescu 639 days ago
There are exactly two activities you can be participating in if you are exploring someone else's undocumented API: (1) free consulting, or (2) illegal hacking. Disclosing vulnerabilities you found in someone else's product, regardless of how obvious, is free consulting. If you're not responsibly disclosing them, then you were illegally hacking their systems.