Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

"I reported the fixation issue privately only because I'm a good guy and was in a good mood."

I for one am glad that Homakov decided to share and write about these security issues rather than just selling it to the highest bidder. I have learned quite a bit over the past year. And it's deplorable that Github isn't paying anything.



He was referring to companies which offer bounties (facebook, google etc) and not sites where you can sell your exploits


yeah. i don't sell exploits yet. Facebook, stripe, shopify, skrill - they treat a reporter nicely.


Any reason why you would even consider selling exploits? Do you not get compensated well from other ventures?


In negotiation theory your 'BATNA' or 'Best Alternative To Negotiated Agreement' is the second choice you'll go with if the current negotiation breaks down. Theoretically, neither party in a negotiation need accept less than their BATNA.

For example, when you negotiate your annual raise, your best alternative is the raise you could get by moving to another employer (adjusted for benefits, time spent commuting, how fun the job is etc). You don't have to explicitly say to your boss "give me a raise or I'll quit" - your boss just needs to know your options are open.

If homakov publicly says he'd never consider selling an exploit, he's saying his BATNA is $0 and some kudos on Hacker News. If he says he's undecided, his BATNA would be somewhere between a few thousand and a few hundred thousand dollars. Needless to say, the former statement closes off a lot of negotiation options while the latter leaves them open.

[0] http://www.forbes.com/sites/andygreenberg/2012/03/23/shoppin...


> Do you not get compensated well from other ventures?

He can likely get compensated much, much better for an original 0day on a big site.


I can only buy some beer and snacks for this compensation


JUST WONDER,

how much would someone pay for this vuln? We can discuss it... homakov@gmail.com


Just because a bounty policy isn't disclosed doesn't mean it doesn't exist.


I've reported several vulnerabilities to GitHub. There is no bounty policy.


yeah +1. @joernchen also did I remember. And lots of other people.

Hey, anyone, is github that super profitable company with 100mln investments ? They got no money or what?


I guess people disclose enough vulns voluntarily that they don't need to offer a bounty as an incentive.


= cheating


trust me, it doesn't exist.


I got a t-shirt some time back for reporting a serious XSS vulnerability.


they like you.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: