logoalt Hacker News

dataflowtoday at 12:42 AM1 replyview on HN

It sounds insultingly low, yeah. I'm trying to imagine why they would pay so little. The only two reasons I can think of are either (a) they were already aware of it and fixing it, and therefore the report didn't really change much, or (b) it requires an unusual configuration or otherwise rare opportunity to that makes it impractical to exploit most users. Really curious to see what the issue was whenever it gets made public.


Replies

solenoid0937today at 12:50 AM

(c) there are so many undiscovered vulnerabilities that it doesn't make sense for them to offer a decent payout