Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's called the GDPR. Places other than the US exist, and the bug reporter seems to be an EU resident.


The GDPR indeed has provisions to fine companies for "avoidable" data leaks due to lacking security practices. The regulators will not pay you a bounty for reporting companies, and there is a big difference between a normal "bug" and "bad practices".

E.g. one of the first GDPR fines here in Germany was issued against a company that had their customer DB dumped[0], specifically for still storing some user passwords in plaintext.

[0] https://gdprhub.eu/index.php?title=LfDI_-_O_1018/115




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: