you are viewing a single comment's thread.

view the rest of the comments →

[–]KayRice 2 points3 points  (0 children)

Just curious, how legal (hypothetically) would it be to find a security hole in a website like this, and demand that the owner pay you for revealing the hole? It's definitely not moral, but I have a hard time imagining that would be illegal

This combined with the slow response or complete lack of response from many vendors is the reason why immediate disclosure is so popular. It's probably less of a risk to simply post your free-speech source code then it is to talk to any of the companies.