← Back to context

Comment by imroot

4 months ago

As someone who manages a bug bounty program, this kind of pisses me off.

For some of our bugs given on h1, we openly say, "Hey, we need to see a POC in order to get this to be triaged." We do not provide test accounts for H1 users, so, if they exploit someone's instance, we'll not only take the amount that the customer paid off of their renewal price, we'll also pay the bounty hunter.