Hacker News new | ask | show | jobs
by piyush_soni 683 days ago
In the Right panel on the page: $1,996,583 Total bounties paid

I don't know if I should feel happy or concerned about the security policies of a company that has already given 2 million USD in bug bounties :).

1 comments

You should be far more concerned about the ones that have given $0.
I want to offer rewards (my site is on H1) but they require I sign up for a minimum $50k/yr subscription to enable that feature. I don't think that's a reason for concern, just means it's a smaller company.
50k a year is insane. It's just a messaging platform. Advertise your own bug bounties and just have them email you, voila.
If you get a lot of reports you'll probably be paying attention least one person 50k/yr to manage it
It means you can afford to be more secure.

Poverty is just a basic gateway. I imagine hackers have to do some calculus on bigger vs little, since usually larger targets are more valuable, buy smaller are likely less secure.