9 ms·
If they don't compensate security researchers enough, the incentive to find security holes goes away. People do this for a living.
by magicarp 13y ago
If they don't compensate security researchers enough, the incentive to find security holes goes away. People do this for a living.
- gradstudent 13y agoMy understanding is that nobody hired these guys to do anything and no bounty was offered for anything. So why should there be any expectation for a financial reward?
- jdiez17 13y agoSecurity researchers' time is valuable. They spend their own time trying to find vulnerabilities that black hat hackers would use against their users, possibly at a profit. They report it to the company giving them a chance to fix their problems. It's called responsible disclosure, and the compensation keeps the smart guys on your side. It doesn't even have to be monetary - for example, GitHub maintains a list[1] of people who have responsibly disclosed vulnerabilities, and they often send them a shirt or something similar. [1] https://help.github.com/articles/responsible-disclosure-of-security-vulnerabilities https://help.github.com/articles/responsible-disclosure-of-s...
- tedunangst 13y agoThis sounds remarkably like how the squeegee men operate in a big city. Oh, hey, I just washed your windshield, you owe me some money. No? Oops, terribly sorry about that scratch as I walked by.
- Yen 13y agoExcept the squeegee men offer a service that you don't really need, and doesn't offer you much value. Responsible disclosure to a company is often much more important than a clean windshield is to you.
- gradstudent 13y ago> Security researchers' time is valuable. Maybe. But nobody asked these guys to do a thing. Ergo, no foul.
- zwp 13y agoOn the flip side, HT Bridge have got way more than 12.50 USD publicity out of this.
- cortesoft 13y agoThis seems to be the entire point of the article - publicity for HT Bridge.