5 ms·
The total amount of these bounties are more or less meaningless. No one can make a living, 1st world wage with them - at least not consistently. All of the prog
by trotsky 15y ago
The total amount of these bounties are more or less meaningless. No one can make a living, 1st world wage with them - at least not consistently. All of the programs will pay you significantly less than what you'd get paid for an equivalent number of hours at a straight job.
What's more, most bugs will sell for 10x the bounty price on the black market.
Bug bounties aren't intended to be competitive compensation. They are intended to be tokens of appreciation given to people who would be reporting the bugs anyway. In this context, $500 vs. $1000 (a more typical reward from the chrome program) isn't too meaningful.
Whether this works for the researcher or not is up to them.
- nbpoole 15y ago+1 At best, a bounty program gives me the incentive to look more closely at a particular website / application. But I've submitted plenty of vulnerability reports to companies that don't have bounty programs. What this bounty really means: if you like finding and responsibly reporting security vulnerabilities, you now have one more reason to spend time doing so on Facebook.