4 ms·
Nobody should have to offer bounties. Researchers should not expect to get paid for their unsolicited work. We probably agree that vulnerability reports should
by hntuesday 10y ago
Nobody should have to offer bounties. Researchers should not expect to get paid for their unsolicited work.
We probably agree that vulnerability reports should be seen as a positive thing. What software owners should have are policies and procedures for transparently handling vulnerability disclosures. At most, I think having some flexible process should be required as part of a certification (PCI, etc).
I do think that knowledge of a vulnerability and lack of action to fix it in a reasonable amount of time, which results in a breach should be treated more seriously. At the same time, encouraging reports of breaches is hard as it is and introducing more punishment would make everyone want to just keep quiet or as ambiguous as possible. I'm not sure what a good solution to this would be.
- cmdrfred 10y ago> Nobody should have to offer bounties. Researchers should not expect to get paid for their unsolicited work. The Chinese and Russian exploit markets don't seem to care if the work was solicited or not.