Hacker News new | ask | show | jobs
by cubefox 2 hours ago
Even if the company doesn't have a big bounty publishing exploit code without warning them is unethical. Moreover, a lot of these projects are FOSS without a company which could pay bug bounties.