3 ms·
> This was a bug that affected multiple products and even crossed into the enterprise suite and google only rewarded $3.3K USD? They could have also offered no
by fractionalhare 6y ago
> This was a bug that affected multiple products and even crossed into the enterprise suite and google only rewarded $3.3K USD?
They could have also offered nothing, which was common up until a decade ago or so. Moreover there isn't a market for security bugs like this, so it's not like Google is underpaying relative to some independent valuation.
The only reason to pay more is out of some ethos that the reporter "deserves" more, but that's not how business works. The value Google obtains by finding any given vulnerability approaches 0. This is why, among other reasons, good product security teams spend most of their time doing things other than searching for vulnerabilities in existing code.