Viewing a single comment thread. View all comments

Autski t1_j24gkz6 wrote

Love their incentive program to pay guys who find bugs like that.

198

asdaaaaaaaa t1_j24nc8i wrote

Bug/vulnerability bounties are a pretty good way to getting results, especially for those hard to figure out ones that deal with a specific issue. Otherwise, there's a much bigger incentive to sell the vulnerability to someone else, or use it for nefarious reasons.

89

imeeme t1_j24w9h0 wrote

Smart way to avoid much larger liabilities.

26

laffer1 t1_j26lhp6 wrote

The downside is that people expect it now from everyone. When you run a small open source project and folks try to hold you hostage to pay, it sucks. Plus a lot of folks do scans all the time hoping to find a vulnerability against your servers

9

ImN0tAsian t1_j279uw3 wrote

Well, the bug-rewarding is in response to extortion via ransomware, so it goes both ways, sadly. I'd rather pay a smaller sum to reward white hats than risk losing an operation.

14