Hacker News new | ask | show | jobs
by saghm 24 days ago
I don't understand why you're confident that those Github issues won't just end up coming later if literally everyone adds this cooldown
1 comments

The security companies looking for and reporting the issues aren't going to use the cooldown too.
They make their money from getting paid by other companies though, don't they? It's hard for me not to imagine that companies in general will see "testing stuff a day later" as a way to cut costs or not paying out as much for bounties because of claims that no one was actually affected yet