Response: https://lobste.rs/s/nz91ga/bug_bounty_ethics
Sounds pretty sketchy.
To be fair, according to the timeline it looks like he did take over a month to report the last vuln after he found it (AWS keypair).
Response: https://lobste.rs/s/nz91ga/bug_bounty_ethics
Sounds pretty sketchy.
To be fair, according to the timeline it looks like he did take over a month to report the last vuln after he found it (AWS keypair).