Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The right amount for a security bounty is the sum of all assets covered by that vulnerability minus $1.

This is the only way companies will take the right processes to protect those assets.



The impact and difficulty of exploit are pivotal parts of assessing the risk of a vulnerability. It doesn’t really matter how many dollars of things are involved if the exploit can’t be exploited or if it’s not a big deal if anyone does.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: