3 ms·
I used to work on the android VRP doing report analysis; I can confidently say that we never intentionally ignored or downgraded reports to save money. There we
by usepgp 8y ago
I used to work on the android VRP doing report analysis; I can confidently say that we never intentionally ignored or downgraded reports to save money. There were a few cases of things slipping through the cracks by missing bug assignees, but the majority of the engineering staff really did want those researchers to get as large of a payout as we could justify, and I imagine other companies/VRPs are in a similar position.
I think the true root cause of the payment discrepancy issue we see in this article is the bias towards believing the vulnerabilities that we find are more significant than they may be. It often can be either a matter of pride, or sometimes just a misunderstanding of the severity guidelines as published.