Hacker News new | past | comments | ask | show | jobs | submit login

I am not sure. Not everybody is driven by money. I know a few people that turned down insane job offers because, as they said, "they are not interested about money." I see the "good guys" saying "I would have report this bug even for free" and the "bad guys" "If I hold on this in the long term, I could be able to keep (or eventually) [put your mad science plan here]"

I guess on average it will reduce those holding on. But it will not eliminate them.




Yes it may not eliminate them but if they hold on too long, someone else may find the same vulnerability and get the reward first. So holding on carries some risk of loss... not just loss of the money, if they really don’t care about that, but also they risk losing the exploit anyway despite holding on.


The change here is that it reduces the "good guys" saying "I would have reported this bug even for free, but if I did I would lose my access to continue researching".




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: