Hacker News new | ask | show | jobs
by dheera 724 days ago
There could also be a reverse bounty paid as a salary bonus to the devs if there is no security bug found in N months. A "code quality bonus", if you will. Though only to encourage quality control.

Intentional bug creation should probably result in firing, unless it was done under duress.