For the past few years, security research has been something I’ve done in my spare time. I know there are people that make a living off of bug bounty programs, but I’ve personally just spent a few hours here and there whenever I feel like it.

Source: Bypassing GitHub’s OAuth flow | Teddy Katz’s Blog