Hacker News new | past | comments | ask | show | jobs | submit login

Because the pay scale is subjective and the reporter doesn't know the amount before they report. FB and others have guidelines for their bounty programs that leave an upward bound open for severe vulnerabilities.

The argument these comments are making is that this report should qualify in some way for a higher payout.

I'm not arguing for either side here, just noting that the comments that you refer to are fairly reasonable.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: