Skip to content

Comment on Ask HN: User wants to disclose a vulnerability. What next?

Comments

Either

"Hi, we do have a bug bounty program, please submit through the link here... Please note, disclosure and all further communication must be through the bug bounty portal"

or

"Hi, unfortunately we do not have a bug bounty program or other compensation, but we would love to address the vulnerability you found, please send details to ..."

That could be you, or a security team mailing list or whatever is appropriate.

Most likely, they'll tell you your site is missing browser security headers or something that they found with a vulnerability scanner, but sometimes there's good reports. Sometimes they'll try to get you to do ad-hoc compensation, which I would refuse (smells like extortion).

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.