← Back to context

Comment by wepple

2 months ago

If I did, would you know?

And if I did, it wouldn’t stop people from doing co-ordinated disclosure either, would it? Same with high end exploits - some folks do co-ord disclosure because it feels good and is great for your CV; others sell gray market and we generally have no idea what’s being traded.

(With the exception of say, zerodium or 0xcharlie’s various talks)

Which of "0xcharlie's various talks" addresses the likelihood of your being able sell a web authz information leak bug on a Google site for bitcoin?