Discovering a vulnerability outside program scope poses an uncomfortable question: how far can I go without legal exposure? This talk examines that boundary in practice: minimal validation, controlled impact, and responsible disclosure—all with one goal: preventing your bug from becoming your legal liability.
Presented at Ekoparty Miami 2026