Hacker News new | ask | show | jobs
by Salgat 39 days ago
This might work but only if the evaluations are done through a trusted third party entity where none of the money ever reaches the company you're submitting to.
2 comments

You only need things like that for non-iterated games. A company that gets a reputation for keeping the money when it's a real bug would stop getting real bug reports.
Weird argument. You're trusting they will pay the bounty if it's a real bug, why not trust they will refund the fee?
Building trust is the hard part, which is why you aggregate all that trust into an entity that everyone else is verifying as trustworthy.
In this case, who is that entity?