frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Ask HN: Bug Bounty Dilemma – Take the $$ and Sign an NDA or Go Public?

11•deep_thinker26•7h ago
Hi everyone,

I recently found a high-criticality vulnerability in a listed consumer company in the UK. It allows unauthorized access to users’ private messages and even lets you impersonate other users on the platform.

They’ve offered a €1,000 bounty, but only if I sign an NDA that prevents any public write-up—even after the issue is patched.

I feel the bounty is too low for the impact, and asking to sign an NDA that prevents any public disclosure even post-fix feels like a big red flag.

I’m leaning towards declining the offer and doing a public write-up once the issue is fixed—but I’d really welcome opinions from others on what the right thing to do here is.

Thanks!

Comments

deepak-singh•7h ago
Your leaning feels correct, and more if the listed company deals with health or financial data where personal data and privacy is of utmost importance.

User-impersonation, and unauthorized access would probably leave them open to potential lawa suits and loss of credibility, hence the NDA or more like a gag order.

Non-disclosure even after patch is surely a big red flag.

In the interest of the users and public accountability, it is suggested to publish an incident report, only after notifying the company of sufficient time to patch the vulnerability.

NitpickLawyer•7h ago
> and doing a public write-up once the issue is fixed

I'd also check with UK laws, as even that might be close to gray-ish territory if they're willing to go after you. Litigious companies are a pain to work with. Especially if they seem to be looking for no bad PR. Worth a few hours of research, maybe reach out to a non-profit and see if they can help?

gtsteve•5h ago
1k sounds like a discretionary amount that would quite neatly fit within a manager's budget for external consultants and so on, which is probably what they'll say you are when accounting for it. They're trying to fly under the radar, and have likely kept this knowledge to only a few people.

The organisation will never change their ways unless they get bad publicity or have to spend so much money that their c-suite gets involved.

I would be wary of trying to negotiate the payment upwards in case you are accused of extortion; just explain you'll disclose publicly in 30 days, which is more than enough time to fix what I assume is a web app backend bug. You don't want them dealing with this kind of issue as a feature to be implemented when there's space in one of the future sprints.

They may try at this point to negotiate the payment upwards, which is a matter for you and your conscience, but I would say that if you don't get something close to 100k, it's likely to be swept under the rug internally and they'll never learn from their mistakes.

Skia Graphite: Chrome's rasterization back end for the future

https://blog.chromium.org/2025/07/introducing-skia-graphite-chromes.html
1•brson•3m ago•0 comments

EU Product Liability Directive impacts software, digital products, cybersecurity

https://www.lexology.com/library/detail.aspx?g=bbef1939-2af0-465a-8b8f-c1ff3ebe9118
2•speckx•3m ago•0 comments

Redis Historical Versions from 2009

https://github.com/antirez/historical-redis-versions
1•philbo•4m ago•0 comments

Analyzing Grok's Latest Meltdown Through Public xAI System Prompts

https://theahura.substack.com/p/tech-things-what-on-earth-is-going
1•theahura•4m ago•0 comments

Show HN: Whispering – An open-source alternative to Superwhisper

https://github.com/braden-w/whispering
1•braden-w•5m ago•1 comments

Physics needs research software engineers

https://www.nature.com/articles/s42254-025-00852-2
1•bookofjoe•5m ago•0 comments

The Magic Theorem

https://aperiodical.com/2025/07/the-magic-theorem/
1•baruchel•5m ago•0 comments

Computer Scientists Figure Out How to Prove Lies

https://www.quantamagazine.org/computer-scientists-figure-out-how-to-prove-lies-20250709/
1•baruchel•6m ago•0 comments

Tree Borrows

https://plf.inf.ethz.ch/research/pldi25-tree-borrows.html
1•zdw•6m ago•0 comments

Florida is letting companies make it harder for highly paid workers to swap jobs

https://www.businessinsider.com/florida-made-it-harder-highly-paid-workers-to-swap-jobs-2025-7
2•pseudolus•8m ago•0 comments

Durable Agent Loops

https://restate.dev/blog/durable-ai-loops-fault-tolerance-across-frameworks-and-without-handcuffs/
1•gk1•9m ago•0 comments

DeCSS (2000)

https://decss.zoy.org/
1•JetSpiegel•11m ago•0 comments

Show HN: Remove metadata from images and documents online

1•Gravyt1•16m ago•0 comments

Show HN: Kinic – A Portable AI Memory Store You Own (Farewell AI Amnesia)

https://www.kinic.io/
2•wyattbenno777•16m ago•0 comments

RNode is an open, free and unrestricted digital radio transceiver

https://unsigned.io/rnode/
2•janandonly•16m ago•0 comments

Show HN: Chain-The-Words game that tests your vocab

https://www.chain-the-words.com/
1•martianmanhunt•17m ago•2 comments

Texas Flood Challenges Faith

https://www.amazingfacts.org/news-and-features/af-blog/article/texas-flood-challenges-faith
1•afaxwebgirl•17m ago•0 comments

Show HN: Pulse – the wearable for n=1 habit experiments

https://blog.pulse.site/pulse-the-wearable-for-n1-habit-experiments/
2•msingh_5•17m ago•1 comments

Using Self-Hosted Large Language Models (LLMs) Securely in Government

https://digitaltrade.blog.gov.uk/2025/07/09/using-self-hosted-large-language-models-llms-securely-in-government/
1•edent•22m ago•0 comments

Has anyone else had issues with the new low calorie sweeteners?

https://tildes.net/~health/1oo1/has_anyone_else_had_issues_with_the_new_low_calorie_sweeteners
1•PaulHoule•26m ago•0 comments

MemOS: A Memory OS for AI System

https://arxiv.org/abs/2507.03724
2•handfuloflight•26m ago•1 comments

Show HN: Nordstars shows a team's missing skills for different business goals

https://nordstars.ai/
2•doraby•27m ago•0 comments

Sh*t Coding – Where sh*t posting and vibe coding meet

https://www.dcoates.com/posts/shit-coding/
3•dustincoates•27m ago•1 comments

Omarchy Is Out

https://world.hey.com/dhh/omarchy-is-out-4666dd31
2•thinkingemote•27m ago•0 comments

Paint: A Timeline

https://kristenroos.ca/timeline
1•surprisetalk•28m ago•0 comments

Induction lamps: fluorescent lighting's final form [video]

https://www.youtube.com/watch?v=SaKKzZRrPIg
1•surprisetalk•28m ago•0 comments

Planes are still decades away from displacing most bird jobs (2022)

https://guzey.com/ai/planes-vs-birds/
1•surprisetalk•28m ago•0 comments

The old traffic math that keeps destroying neighborhoods

https://www.fastcompany.com/91362348/road-design-traffic-math-destroying-neighborhoods-los
2•toss1•28m ago•0 comments

Show HN: I made a tool that gets you customers from Reddit

https://www.bazzly.ai/
1•FilipPanoski•29m ago•1 comments

Show HN: Stravu – Editable, multi-player AI notebooks with text, tables, diagram

4•wek•29m ago•0 comments