Ask HN: Bug Bounty Dilemma – Take the $$ and Sign an NDA or Go Public?
22 points by deep_thinker26 5 days ago
Hi everyone,
I recently found a high-criticality vulnerability in a listed consumer company in the UK. It allows unauthorized access to users’ private messages and even lets you impersonate other users on the platform.
They’ve offered a €1,000 bounty, but only if I sign an NDA that prevents any public write-up—even after the issue is patched.
I feel the bounty is too low for the impact, and asking to sign an NDA that prevents any public disclosure even post-fix feels like a big red flag.
I’m leaning towards declining the offer and doing a public write-up once the issue is fixed—but I’d really welcome opinions from others on what the right thing to do here is.
Thanks!
This is exactly how bug bounty hunters are being exploited for.
Though it is on the good side about disclosure, calculate how much financial, reputation impact, negative publicity would cost the company and settle for a fair price and not a measly sum of 1k EUR.
It is a huge red flag to keep it under the radar if they think the impact is going to be high. I'm sure it is high and that's the reason they want to keep it undisclosed while they silently patch it.
One question: Was the discovery part of a bug bounty program? Or you stumbled upon it without any actual request? I'm trying to see the legal angle that might get down played there if you do not have the authorization to look at it.
Being ethical is the only advantage I see if that is the case. Else, you should negotiate and demand a fair price and go for a public disclosure which will cause more harm than good for them.
Everything has a price. Nothing in this world is free. Contact some good lawyer.
Don't ever sign an NDA without vetting it out with a good lawyer. Fine prints matter a lot.
As some of the fellow HNs mentioned, they will probably be looking at a huge impact and the reason for the NDA and a low sum as a token appreciation. They think they can buy their way being a corporate, any my advice would be to talk to some lawyers or contact a non-profit to help sort things out.
Probably you could donate a % to them if you get a good amount.
Hope you get what you deserve.