|
|
|
|
|
by anthonyryan1
333 days ago
|
|
As the only developer maintaining a big bounty program. I believe they are all trending downward. I've recently cut bounties to zero for all but the most severe issues, hoping to refocus the program on rewarding interesting findings instead of the low value reports. So far it's done nothing to improve the situation, because nobody appears to read the rewards information before emailing. I think reading scope/rewards takes too much time per company for these low value reports. I think that speaks volumes about how much time goes into the actual discoveries. Open to suggestions to improve the signal to noise ratio from anyone whose made notable improvements to a bug bounty program. |
|