Hacker News new | ask | show | jobs
by dannyw 1800 days ago
Because ZDI negotiate. As a bug bounty participant in the official programs, you aren't allowed to negotiate.

ZDI, on the other hand can say: "We want $10M for this iOS zero day, or we don't report it to you." And the process of negotiation goes back and forth, but the end result is, Apple will pay considerably more to ZDI than through the direct program.

1 comments

Correct me if i am wrong. I think another reason why ZDI maybe could pay more is because they also have other paying customers that pay for IDS/IPS subscription.