Hacker News new | ask | show | jobs
by ejcx 3582 days ago
Not only to GET press, but also to PRESS the company for $.

This is a huge problem I see with bugbounties. People running the bug bounties, who are not appsec security literate, are basically bullied in to thinking that something is a security risk when it is not quite often.

I deal with people trying to do this 10-15 times per week. I can totally see how people get pushed in to paying thousands for essentially worthless bugs.