Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The researcher doesn't have zero knowledge before choosing to work with/for a company. The history of payouts and the perception of the company in the community are meaningful indicators of willingness to pay.


A large number of companies keep their bug bounty payouts and reports permanently private, which I feel is a disservice to the community.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: