|
|
|
|
|
by K0nserv
3619 days ago
|
|
The concern with the low payout is that it's supposed to be a way to compensate white hat hackers and dissuaded them from going to the black market with security problems like this. Given the business that LastPass is in wouldn't you agree that it's extremely crucial they make sure white hat hackers are aptly compensated for serious problems they find? In fact I'd think it'd be reasonable for them to pay more than Facebook for certain classes of bugs(like this one). After all all your passwords are more valuable than your Facebook account. |
|
The purpose of a bug bounty is to incentivize researchers to target specific pieces of software so that vendors can benefit from that attention.