3 ms·
Maybe needs a Good-Guy-Buy-It-Now w/instant delivery at a fair price. (OK that’s kind of a threat—you’re running an auction and you have the price the corp has
by Barbing 1mo ago
Maybe needs a Good-Guy-Buy-It-Now w/instant delivery at a fair price. (OK that’s kind of a threat—you’re running an auction and you have the price the corp has to pay to avoid the auction ending.)
$1k is so dumb and the fact we’re discussing auctions is proof (hello, Sundar, what you doing over there?).
Guess this will change after the next e.g. nationwide hospital ransomware by a hacker who publicly laments bounty rates, if the news cycle accommodates the story long enough.
- eru 1mo ago> Guess this will change after the next e.g. nationwide hospital ransomware by a hacker who publicly laments bounty rates, if the news cycle accommodates the story long enough. Negotiating with terrorists or black mailers is a bad idea.
- Barbing 1mo agoAgreed. Paying security researchers fair rates is a good idea though right? Keeps future researchers honest?
- eru 1mo agoMaybe. But as soon as they threaten to sell it to the baddies or use it for ransomware themselves, I would cease all communication and negotiation. The legitimate threat the researcher has is to disclose to the general public. (And to disclose the next bug to the general public, if there's no good payment.)