logoalt Hacker News

gamer191today at 7:18 AM1 replyview on HN

Agreed, although the reimbursement should be based on whether a reasonable person could consider that to be a vulnerability. Often it’s tricky for outsiders to tell whether a behaviour is expected or a vulnerability


Replies

dlcarriertoday at 9:13 AM

Yeah, the reimbursement would need to be for a good-faith submission worth considering, even if it wasn't actionable.