Hacker News new | ask | show | jobs
by lnenad 25 days ago
You understand the concept of doing something that doesn't bring direct monetary benefit?
4 comments

He makes a point, though: bug bounties exist to incentivize people to find and report bugs to a company. We talk about white, gray, and black hats, roughly based on their level of ethics. For black hats – and some gray hats – money is one of the big reasons they look for vulnerabilities.
Yes I do, but we are speaking of companies with billions. If they can't take this seriously enough that they pay for the vulnerabilities, they deserve to get the bad press.

When all MSI computers get exploited in the wild, I bet that these execs will find money.

But it's not "MSI computers" it's actual people getting pwned.
I know but I don't think there is any other solution. These companies speak money, if you don't speak money they ignore you.

Getting your users computers infected and having to deal with bad buzz, prosecutions, loss of sales, would most likely wake them up.

Sending them a mail ? They don't care.

If it's my data/money getting stolen, I'd give no fucks about MSI getting a fine or whatever the usual reaction to these fuckups is. On the other hand, if I found an exploit and there wasn't a bounty available, I'd still report it. Betterment of the world and all that.
you understand the concept of zero days ?

companies should be better and if not, criminally liable for their bad code.

I don't think you thought this through.

does this also apply to individual developers?

should Linux Torvalds or the ffmpeg developers go to jail if they merge a RCE zero-day into the Linux kernel or into ffmpeg?

gross negligence / honest mistake

if you cannot differentiate the 2, :insert rude thing here:

ok, so you agree that if Linus merges code due to gross negligence, for example he was warned in an email that it contains a RCE and he laughs it off, and still merges it, he should go to jail

glad you are consistent in your beliefs

Ok? I agree with everything. What does that have to do with reporting exploits that don't have bounties?
In other words, bootlicking the corpo-authoritarians?
You're actually helping the people that use the software from getting pwned, companies are secondary beneficiaries.
Keep toeing the line and help them put the nooses around your necks.
What wild regurgitation of some generic sentence is this lol?