48

paraphrased

C: "hey, we've seen the ticket resolved with a bug bounty rewarded to you! congratulations!"
C: "we've talked about it today on our meeting and think we deserve 85% - since it was discovered by you while working on our contract and system!"

That was so bizarre to me and I was speechless for a good 10 minutes, didn't even have any witty reply afterwards.

I just cancelled the contract, reported the client to my middleman, explained it to the on-sight business contact and requested the final milestone to be released with one week notice until it gets to be a public case if not released through escrow.

I'm still somewhat shocked at how greedy one can be, the whole system package I was working on had estimated 150-300k post first week launch (tons of existing clients merged and unified into one system, with much more paid and feature stuff etc.), the bounty I got was around 3.5k, it still didn't sink in me.

Comments
  • 10
    Wow... That's fucked up.
  • 12
    Wait, whaaat?

    If they wont give you 100% I would just spread black PR and give no fucks to be honest.
  • 6
    Are you trying to get rid of the client (I assume you are kind of freelancer)?
  • 12
    @DubbaThony I worked for company X, found a bug/security issue in tool/framework Y in use and reported it, because that would allow RCE, they confirmed and released the bounty, now company X read the ticket and wanted a piece of the pie, because I "found it while working for them"...
  • 7
    @joas not trying, I already did, that's really a vile thing to even propose or have pass a fucking MEETING of people over that.
  • 3
    @JoshBent now this is a true rant. Wish you the best!
  • 3
    @JoshBent

    Sigh... Okay, i missinterpreted that, but yeah, thats just plain greed. I have nothing more to say....
Add Comment