Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> There are many wannabe security researchers who find issues that are definitely not exploitable, and then demand CVE numbers and other forms of recognition or even a bounty

I believe this has happened to curl several times recently.



It happens constantly to any startup with a security@ email address.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: