|
|
|
|
|
by oskarsv
2115 days ago
|
|
Yes they should and I think I could. This exploit was more of a fun challenge. I support and agree to everything you are saying. I love the community response. I too loathe the bug bounty asymmetry in power between corporations and reporters, but it exists.. by design. How do you imagine a researcher can 'demand' more money in this situation? They can choose the amounts arbitrarily and there is nothing legal or ethical you can do about it. I haven't seen any proposals for real solutions - how would you ask this? How do you decide the amount for each company? Solutions, which do not bypass ethics or laws. I hope that 'the market' will solve this eventually and I think I at least raised awareness. |
|
Would you have done without excepting any rewards, i.e. just for fun?