Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I generally agree with you, but I would worry that an overzealous agency would be fine with finding and reporting the SQL injection vulnerability but object to the author creating an obviously fake record. It's hard to know exactly where the line is.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: