Viewing a single comment thread. View all comments

laffer1 t1_j26lhp6 wrote

The downside is that people expect it now from everyone. When you run a small open source project and folks try to hold you hostage to pay, it sucks. Plus a lot of folks do scans all the time hoping to find a vulnerability against your servers

9

ImN0tAsian t1_j279uw3 wrote

Well, the bug-rewarding is in response to extortion via ransomware, so it goes both ways, sadly. I'd rather pay a smaller sum to reward white hats than risk losing an operation.

14