|
|
|
|
|
by tptacek
645 days ago
|
|
Vulnerability researchers misapprehend the dynamics of bug bounty programs all. the. time. and are virtually never doing that in bad faith. I don't need to determine which of these two entities are above board; I presume they both are. If you think that any major vendor bug bounty has incentives to stiff researchers, I'm commenting to tell you that's a strong sign you should dig deeper into the dynamics of bounty programs. They do not have those incentives. |
|
This is not from an examination of when bug programs work but when they have very demonstrably not worked in the past.