Hacker News new | ask | show | jobs
by rapind 1980 days ago
Bug bounties are ridiculous. If you disclose in an “irresponsible” way you’d get shamed here on HN, and yet we almost never talk about how pitiful the rewards are for “responsible” disclosure (maybe nothing or even legal trouble!).
3 comments

Honestly, I’m all for irresponsible disclosure if corporations pay irresponsibly low bounties.

We need to disabuse corporations of the idea that they deserve responsible disclosure when they pay paltry sums for serious bugs.

> yet we almost never talk about how pitiful the rewards are

We almost always talk about how pitiful the rewards are, every time someone discloses a pitiful reward. Your post is doing exactly that.

The bounties can actually be rather good. This one just seems disproportionately low.