• Telorand@reddthat.com
    link
    fedilink
    arrow-up
    15
    ·
    edit-2
    1 day ago

    why anyone would trust these companies to pay out

    AFAIK, they historically have

    why anyone would help them fix their problems at this point

    They’re not “helping,” they’re trying to get paid by finding exploits legally, rather than using them illegally. And if someone is particularly good, it can be lucrative work. It’s historically been a mutually beneficial arrangement, so it’s ironic if M$lop thinks they can cut out human researchers (ostensibly swapping them for AI agents) and still maintain a secure codebase.

    To me, this is M$lop trying to cut costs from the wrong thing; may they get what they deserve.

    ETA: and if they make it impossible to make a living at reporting exploits legally, there’s really only one option left to make a living…