Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Splitting the bounty does nothing to fix the incentive problem, since it's the same outlay from the vendor whether they fix after 1 report, or a year later after 20.

In reality, vendors (or at least, serious vendors) aren't gaming H1 to stiff bounty hunters. If anything, the major complaint vendors have about H1 is that they aren't paying enough --- that is, they deal with too many garbage reports for every report that actually merits a fix.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: