|
|
|
|
|
by remus
1979 days ago
|
|
> And is basically nothing compared to the value of "exploiting" this bug. Out of interest, how do you think you'd go about monetising this bug? I agree that the information leakage is definitely bad, but exploiting that to turn it in to cold hard cash seems tricky at best imo. I presume this factors in to Google's payout calculations. |
|
And no, how much it could be monetized certainly shouldn't factor into lowering the bounty. Maybe when raising it, since you need to be competing with the black market, but an exploit should be valued only on how much damage it could cause, and getting people disappeared for watching anti-government videos sounds like pretty big damage.