|
|
|
Ask HN: Security Vulnerability Rewards
|
|
4 points
by shivang
4190 days ago
|
|
Hi, You are working on a product and the product is still in the beta stage, and someone out of the blue sends an email to you that your site has these security vulnerabilities(valid ones) and asks for rewards in return. Has anyone faced this kind of situations? We are willing to give him the reward, but being in beta stage, we are still not sure as to what and how much we should reward him. |
|
If someone finds a vulnerability accidentally (I've done this before), they won't ask for a reward if they are professional and the company has no bug bounty. It's reasonable to tell a company out of respect - it's unreasonable to ask for payment, that implies almost a ransom and will encourage more of it.
There is a problem with bug bounties these days in that they attract a lot of people desperate to get into the InfoSec industry who don't necessarily know what they're doing and have no professionalism (see @CluelessSec for example.) Don't encourage it by giving a reward.
Cold calling (or emailing) companies to solicit penetration testing is okay, casing the company for vulnerabilities and asking for payment is not. I do suggest you find someone to do a solid penetration test of your company however just out of principle.