As a high school senior, Ben Brundage found two major security vulnerabilities in Dutch government websites during an open bug-bounty program, earning only a t-shirt.
Snapshot · The Journal.
As a high school senior, Ben Brundage found two major security vulnerabilities in Dutch government websites during an open bug-bounty program, earning only a t-shirt.
Where this was said
At 10:20 · chapter starts 4:43
Long before he was fighting the world's biggest botnet, Ben Brundage was just a kid who liked hiking and skiing. That changed in 2020 when COVID lockdowns drove him to Minecraft, and the game's modding system sparked a genuine love of code [1] — Benjamin Brundage "Bored during COVID lockdowns, teenager Benjamin Brundage started modding Minecraft and quickly fell into Discord servers where cybercrime w…" 04:44 . Ben learned Java by watching late-night tutorials, built custom plants and creatures, and then discovered the darker side: cheats that let him see through walls and auto-aim at enemies, eventually getting his account banned. On Discord, Minecraft modding communities blurred almost imperceptibly into hacker forums — servers on cybercrime were just a few hops away. Ben recounts how easy it was to get drawn in, describing the normalization that happens when you spend enough time around people who treat cybercrime as routine. His moral alarm bells finally rang when he stumbled on a list of 100 stolen Spotify Premium accounts posted openly in a server — rather than join in, he emailed all 60-some account holders to warn them, a decision that set the direction of his life.
Bored during COVID lockdowns, teenager Benjamin Brundage started modding Minecraft and quickly fell into Discord servers where cybercrime was openly discussed. He saw a stolen list of 100 Spotify accounts and chose to warn the victims instead of joining the hackers.
As a high school senior, Ben found two major security bugs in Dutch government websites during an open bug-bounty program. His reward: a black t-shirt reading 'Hacked the Dutch government, and all I got was this lousy t-shirt.' It was a dopamine rush anyway.
Ad-based monetization works well for game apps where users spend extended time in-session, as seen with Grid and Wordle.
Tool-focused apps like PuffCount are poor candidates for ad monetization because users don't stay in-session long enough.
A hard paywall is a screen that blocks all app features unless the user pays or starts a free trial — it cannot be dismissed.
Mobile apps are primarily monetized through either ads (best for games) or in-app purchases/subscriptions (best for tools).
According to the episode, YouTube outperforms every other social platform for building trust and driving SaaS conversions.
Vasco stated that the majority of his app's user base came directly from his YouTube channel.
SEO Bot features a 'Boost My Domain Rating' button that routes users directly to Listing Bot, an example of in-product cross-selling.
The founder's entire product portfolio is AI-related, making it easier to package products attractively for directories.
The founder attached their SaaS demo to the trending debate about whether AI coding is actually good enough to build a full SaaS product.
We use essential and analytics cookies to run Vuci. To understand how the site is used: Privacy Policy.
Install Vuci on your phone
Add it to your home screen for a faster, app-like experience.
Install Vuci on your phone
Tap the Share button, then “Add to Home Screen”.
A new version is available
Reload to get the latest Vuci.