2 ms·
I think that's a bit different. for real security bugs, like, you can literally sell them to brokers who sell them to governments. would selling stuff to the C
by r_lee 18d ago
I think that's a bit different.
for real security bugs, like, you can literally sell them to brokers who sell them to governments. would selling stuff to the CIA be ghetto?
morally, it depends. but after seeing so many posts of e.g. Google cheapskating on bug reports, it really makes no sense to me to participate in such a broken system.
this case however is quite different as it was a B2B encounter and during vendor vetting
like to me it just seems like a fair deal, if Google wants their bugs patched (which they can definitely afford to do) they'd just pay properly for serious bugs and so on, and everybody would be happy. it's not some kind of thing where they can't do anything about.
maybe you can understand the angle I'm coming from?