Hacker News new | ask | show | jobs
by droopybuns 4523 days ago
It is a mistake to assume that bug bounties exist to compete with black market prices.

I argue that bug bounties are a pressure release valve for people who know that there's a problem, but are unsure if they're at risk of getting lawyer'd or prosecute'd for disclosing vulns.

No private entity can compete with nation states for vulnerability rewards.