• rustydrd@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    94
    ·
    17 hours ago

    I guess it’s one of those “justifiable but unwise” sort of things. If your company is doing a bug bounty program to stay on top of security vulnerabilities, what you don’t want is to create the perception that the work of devs who look for these vulnerabilities isn’t appreciated, for example, by skimping on bounties over technicalities.

    Paying the 10k doesn’t ruin the company and allows them to fix a section of code that may become a vulnerability in the future. Not paying the 10k saves them 10k at the price of the devs’ trust that keeps this program effective. From a financial point of view, this is some very poor decision making.

    • Smoogs@lemmy.world
      link
      fedilink
      English
      arrow-up
      15
      arrow-down
      2
      ·
      edit-2
      13 hours ago

      Sure however it’s still worth calling out click bait headlines and reactionary posters are all being bad actors here in the misinformation spread.

      Probably more important as then developers don’t back out over being emotionally manipulated by fake bullshit.