If someone finds a vulnerability in a website that has an active bug bounty program, is the bounty hunter contractually obligated to disclose the vuln?
10
2
1
15
Replying to @jeremiahg
It depends how you found vuln and if BB requires disclosure. If found via normal website usage, then no. If you security test to find it and BB requires disclosure, then yes. BB = permission to test (with conditions). Security testing while violating BB terms = illegal in US.

Feb 7, 2019 · 8:54 PM UTC

1