|
|
|
|
|
by tomlongson
3833 days ago
|
|
The hypothetical question Facebook should ask is: "If the security researcher did not disclose the RCE, but instead sold it to highest bidder, how much would that likely pay in this situation?" Paying security researchers to properly disclose is a way of financially encouraging the right behavior. While it may be tough to stomach a large payout for responsible disclosure, do you really want them considering the alternative? It's like tipping in a restaurant to ensure food quality. |
|