Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It appears Heartbleed has riled up the Hound dogs. It's unfortunate the funds aren't available for bug bounties in OpenSSL.



Beware of the chilling effects of collecting Google bounties, they will claim a reward is invalid if you've blogged about the vuln outside of their timetable.


Isn't that common sense? If you disclose the bug publicly before it's patched you won't get the reward...


Sort of. But Google has a history of how it treats independent researchers.


The prize money could stand to be a whole lot larger however.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: