Live data from Hacker News

Hacking Github with Webkit

homakov.blogspot.com

21–30 of 82 posts

Re: Hacking Github with Webkit

#23
post #7
post #4

Earlier quoted context omitted.

yeah. i don't sell exploits yet. Facebook, stripe, shopify, skrill - they treat a reporter nicely.

Any reason why you would even consider selling exploits? Do you not get compensated well from other ventures?

> Do you not get compensated well from other ventures?

He can likely get compensated much, much better for an original 0day on a big site.

Re: Hacking Github with Webkit

#25
post #2

"I reported the fixation issue privately only because I'm a good guy and was in a good mood." I for one am glad that Homakov decided to share and write about these security issues rather than just selling it to the highest bidder. I have learned quite a bit over the past year. And it's deplorable that Github isn't paying anything.

Just because a bounty policy isn't disclosed doesn't mean it doesn't exist.

Re: Hacking Github with Webkit

#26
post #25
post #2

"I reported the fixation issue privately only because I'm a good guy and was in a good mood." I for one am glad that Homakov decided to share and write about these security issues rather than just selling it to the highest bidder. I have learned quite a bit over the past year. And it's deplorable that Github isn't paying anything.

Just because a bounty policy isn't disclosed doesn't mean it doesn't exist.

trust me, it doesn't exist.

Re: Hacking Github with Webkit

#28
post #25
post #2

"I reported the fixation issue privately only because I'm a good guy and was in a good mood." I for one am glad that Homakov decided to share and write about these security issues rather than just selling it to the highest bidder. I have learned quite a bit over the past year. And it's deplorable that Github isn't paying anything.

Just because a bounty policy isn't disclosed doesn't mean it doesn't exist.

I've reported several vulnerabilities to GitHub. There is no bounty policy.

Re: Hacking Github with Webkit

#29
post #25

Earlier quoted context omitted.

Just because a bounty policy isn't disclosed doesn't mean it doesn't exist.

I've reported several vulnerabilities to GitHub. There is no bounty policy.

yeah +1. @joernchen also did I remember. And lots of other people.

Hey, anyone, is github that super profitable company with 100mln investments ? They got no money or what?

Post reply on HN