Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The biggest reason I see for the payouts is simple:

That exploit has a value on the 'black market'. If it comes down to "no money" or "$20k", people are going to be looking at the "something" instead of "nothing", no matter what the laws say.

The bug bounties don't always have to be a lot - most people will want to do the right/safe thing anyway. They just have to offer some incentive (we've all seen some success with even $800 bug bounties) to keep the honest people honest.



If someone needs a monetary incentive to be honest then they're not honest, in fact they're quite the opposite.


I don't agree that the motivation would be to keep the honest people honest.

There's nothing wrong with having a talent and wanting to make a living from it.


On the contrary, we're in the position to do an incomparable disservice to the world. Companies buy exploits simply to buy the hacker's silence, and governments buy exploits to bolster their offensive military capabilities -- when we sell to them we're complicit with the damage they do.

Personally I'm of the opinion that the only responsible disclosure is full and anonymous disclosure.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: