3 ms·
If you participate in a bug bounty program you already decided you will not sell it on The Market. As such you should be payed for your effort and time at least
by GoToRO 8y ago
If you participate in a bug bounty program you already decided you will not sell it on The Market. As such you should be payed for your effort and time at least. Otherwise you sell it to whoever pays more (on The Market).
If you read how much effort is put into just reporting the bug, that will come close to a half month at least. Is $1000 half a security research's salary?
- zulln 8y agoThat is a strange way of thinking about it. Should not Facebook instead incentivize the kind of bug they are interested in, rather than caring how long time it took to find?
- GoToRO 8y agoThey should evaluate fairly how much damage that bug would produce if used by bad actors and pay a percent of that. This is how I see it. Otherwise they are just relying on someone's passion and ethic to stay safe.
- tptacek 8y agoThat's essentially what they are doing. You just dispute the percentage they assign.