Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

He was referring to companies which offer bounties (facebook, google etc) and not sites where you can sell your exploits


yeah. i don't sell exploits yet. Facebook, stripe, shopify, skrill - they treat a reporter nicely.


Any reason why you would even consider selling exploits? Do you not get compensated well from other ventures?


In negotiation theory your 'BATNA' or 'Best Alternative To Negotiated Agreement' is the second choice you'll go with if the current negotiation breaks down. Theoretically, neither party in a negotiation need accept less than their BATNA.

For example, when you negotiate your annual raise, your best alternative is the raise you could get by moving to another employer (adjusted for benefits, time spent commuting, how fun the job is etc). You don't have to explicitly say to your boss "give me a raise or I'll quit" - your boss just needs to know your options are open.

If homakov publicly says he'd never consider selling an exploit, he's saying his BATNA is $0 and some kudos on Hacker News. If he says he's undecided, his BATNA would be somewhere between a few thousand and a few hundred thousand dollars. Needless to say, the former statement closes off a lot of negotiation options while the latter leaves them open.

[0] http://www.forbes.com/sites/andygreenberg/2012/03/23/shoppin...


> Do you not get compensated well from other ventures?

He can likely get compensated much, much better for an original 0day on a big site.


I can only buy some beer and snacks for this compensation


JUST WONDER,

how much would someone pay for this vuln? We can discuss it... homakov@gmail.com




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: