Hacker News new | ask | show | jobs
by jfoster 4640 days ago
You're right. As a result, white-hats should spend zero time with Yahoo (as the company in the article has indicated they will). The result of that is that only black-hats will be finding Yahoo vulnerabilities. Not a good end result.

What should happen is that Yahoo should have bounties in the first instance. They don't have to, but not having them leads to a bad outcome for everyone except black-hats.