← Back to context

Comment by Trundle

8 years ago

Have you asked them for an eta on your shirt?

You know a company isn't serious about security when their top security bounty is a t-shirt. Instagram has a better policy, for God's sake.

  • I'd love to see some evidence that big bounties correspond to more exploits being found. In my experience, they tend to result in an increasing number amount of crap for your security team to sort through.

  • Plenty of companies that are serious about security don't do bounties. They're a real pain to administer apparently

    • I'd expect for a company that can MITM a good chunk of the Internet to incur that pain in exchange for all the money customer pay them.