Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

With those lower 'underlying project' bugs there are multiple actors who can compensate for vulnerability research, so the market rate goes down.

It makes sense to either: lower the payout to reflect market rate or start a seperate scheme for those projects that others can buy into. Unfortunately if you use a seperate scheme you end up paying for bugs that don't affect you.

Personally I'd have split my own payouts into things from my own project (100%) and things from other projects (10%).

The fact they haven't done this suggests to me that they consider the bounty system too expensive - either in payouts or maintenance. By reducing payouts you will likely reduce interest and increase signal to noise at the cost of less signal.



or send the signal to other less well intentioned parties who see the value of owning vulns to popular underlying libs


I don't know how strong that argument is, yet I suspect not very.

The problem with selling to 'less well intentioned parties' is that they are hard to get a hold of, hard to trust, and time consuming to work with. I very much doubt that many people who sell to them are not already close to them and their ilk. I also see this much like the arms trade, where illegal trading is an intrinsic property of the trader, not a function of the market.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: