Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This has nothing to do with it.

See sibling comments for the actual reason: Facebook and other companies typically allow this kind of security research, as long as the intent is not malicious and the researcher operates within some boundaries.



This has everything to do with it. It is much easier for pentesters to do their job when they don't have to walk on eggshells.

Any U.S. based pentester would always think twice before logging in a compromised system.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: