Responsible disclosure in a game

How long would one wait after notifying a developer about a glitch in a game, one that could cost revenue drops to the devs, before notifying the user base in general.

I've never done this before, even when I've found bugs in the past. I just noted it and kept my head down

I won't list the game, but I've managed to manipulate a game that might normally cost money to play without having to pay to gain rewards.

I told the dev, but how long should I wait before going public? Its a dumb hack, but a hack that keeps the dev from earning money they're entitled to.

30 days seems like more than enough. unless I'm doing it wrng

submitted by /u/ForSquirel
[link] [comments]

from hacking: security in practice https://ift.tt/iKGXVjT

Comments