|
|
|
|
|
by encoderer
3838 days ago
|
|
I don't know much about this which is why I asked. It seems that severity-based payouts have created incentives that do not match the program rules? Maybe all rce bugs should be paid out on an assumption that if used they'll lead to access to a shell or to user data. |
|