Hacker News new | ask | show | jobs
by psykovsky 3987 days ago
Only way to be sure it exists is to test it live.
2 comments

That is rarely true, and also besides the point: if you report the flaw and they acknowledge it, what does verification matter?
Not only did he test it live, but he used the gift card to purchase items. Could have easily walked in and checked the balance without purchasing anything.
To be fair, his purchase was relatively inexpensive, did not significantly disrupt other customers or otherwise compromise the system, and served to test that the balance was actually available, not just displayed.

Just deduct the price of the sandwiches from the bounty reward?