Hacker News new | ask | show | jobs
by RangerScience 3621 days ago
"You agree not to disclose the full amount awarded you as part of this bug bounty award contract."
1 comments

If the full amount is <=1000 it's irrelevant what you're actually awarded for a bug as serious as this.
Oh, no - I mean, if you want to reward people fairly, but not get a stampede to your door, tell them to report a smaller bounty than was received. They can spread private word to their network (presumably, other people who are going to actually be correct) but still provide hooks to the public.

Probably doesn't work out, but it's what came to mind as a way to deal with the balancing act.