|
|
|
|
|
by astrange
212 days ago
|
|
The problem with security reports in general is security people are rampant self-promoters. (Linus once called them something worse.) Imagine you're a humble volunteer OSS developer. If a security researcher finds a bug in your code they're going to make up a cute name for it, start a website with a logo, Google is going to give them a million dollar bounty, they're going to go to Defcon and get a prize and I assume go to some kind of secret security people orgy where everyone is dressed like they're in The Matrix. Nobody is going to do any of this for you when you fix it. |
|
Doesn't really fit with your narrative of security researchers as shameless glory hounds, does it?