Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I have never once heard of a bug bounty being paid to a former employee let alone to the same person who wrote the code. It strikes me as something that is likely to do damage to ones reputation far out of proportion the few thousands of dollars one might hope to gain.


I received a bug bounty from Mozilla after leaving, in a browser component I previously worked on. I didn't write the vulnerable code though.

On the other hand, Google refused to pay me a bug bounty for a bug I found in the same component, in part because I used to work on it when I was at Mozilla, even though I didn't write the vulnerable code.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: