Live data from Hacker News

The Bank Job – breaking a mobile banking application

boris.in

1–10 of 42 posts

Re: The Bank Job – breaking a mobile banking application

#3

The post is interesting, but I do not know why people assume they would get a bounty for a security report if the company does not have responsible disclosure / bounty program.

Probably from goodwill. Sadly the bank couldn't afford it, they can afford getting stolen from anyway. The bank always wins.

Re: The Bank Job – breaking a mobile banking application

#4

The post is interesting, but I do not know why people assume they would get a bounty for a security report if the company does not have responsible disclosure / bounty program.

If the bank doesn't have a disclosure/bounty program, you can easily end up getting yourself arrested.

Re: The Bank Job – breaking a mobile banking application

#5

The post is interesting, but I do not know why people assume they would get a bounty for a security report if the company does not have responsible disclosure / bounty program.

It would be common sense to pay a bounty. Similar to the reward you should get if you find somebody's wallet. If you are known for not paying a bounty (a finder reward) some people will not tell you your security holes (will not give you back your wallet).

On the long run this will be more expensive than the bounty. But the problem might be that if the would pay a bounty, they would admit that the screwed it, what their lawyers would like to prevent.

Re: The Bank Job – breaking a mobile banking application

#7

The post is interesting, but I do not know why people assume they would get a bounty for a security report if the company does not have responsible disclosure / bounty program.

OP here. I knew the bank wouldn't pay. But I wanted to initiate a discussion with the bank so they know that paying bounty for disclosures is a thing.

Re: The Bank Job – breaking a mobile banking application

#8
post #5

The post is interesting, but I do not know why people assume they would get a bounty for a security report if the company does not have responsible disclosure / bounty program.

It would be common sense to pay a bounty. Similar to the reward you should get if you find somebody's wallet. If you are known for not paying a bounty (a finder reward) some people will not tell you your security holes (will not give you back your wallet). On the long run this will be more expensive than the bounty. But the problem might be that if the would pay a bounty, they would admit that the screwed it, what th…

I would absolutely never expect or even accept a reward for a lost wallet. It's our duty as a member of a civilized society to not steal.

If a wallet finder failed to give me my wallet back, I'd just call the police.

Re: The Bank Job – breaking a mobile banking application

#9
post #5

Earlier quoted context omitted.

It would be common sense to pay a bounty. Similar to the reward you should get if you find somebody's wallet. If you are known for not paying a bounty (a finder reward) some people will not tell you your security holes (will not give you back your wallet). On the long run this will be more expensive than the bounty. But the problem might be that if the would pay a bounty, they would admit that the screwed it, what th…

I would absolutely never expect or even accept a reward for a lost wallet. It's our duty as a member of a civilized society to not steal. If a wallet finder failed to give me my wallet back, I'd just call the police.

The options aren't just returning it or stealing it, they can simply leave it where it is to avoid the hassle of having to return it. Hence why having a custom of paying a reward might be beneficial for wallet losers in general.
Post reply on HN