470
you are viewing a single comment's thread
view the rest of the comments
[-] ganksy@lemmy.world 19 points 8 months ago

Do they directly show(sell maybe) the exploits to the companies?

[-] uriel238@lemmy.blahaj.zone 42 points 8 months ago

White hats can be prosecuted via the CFAA. they usually aren't (most of us are guilty of CFAA penalties) but some companies got sour to fixing their web security and instead would sue and push to prosecute.

So in the early 2010s the white hat community went gray to survive. And companies that don't pay their bounties oe cause trouble don't get pen tested by white hats (at least not when wearing a white hat).

[-] Patches@sh.itjust.works 5 points 8 months ago

How do you know if a company is going to pay to fix?

Do you just have to take a chance and notify them?

Either I make a bunch of money, or they say fuck off, or they send me to jail? It seems too iffy

[-] aksdb@lemmy.world 2 points 8 months ago

I assume the idea is, that the company then has a contract with the hacker, so they can no longer sue him. They essentially hack themselves via proxy.

[-] ganksy@lemmy.world 4 points 8 months ago

Thank you! I appreciate the insight.

[-] WallEx@feddit.de 28 points 8 months ago* (last edited 8 months ago)

Thats what white hats would do and what these contests are usually for

But its more like a bughunt with an open Bounty then selling afaik

this post was submitted on 28 Jan 2024
470 points (99.2% liked)

Technology

58737 readers
4217 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS