Comment by ralph84
14 hours ago
The researcher in this case was doing a security review for their company who was a potential customer. Sending potential customers more than a token amount of cash is usually prohibited by corporate ethics rules for obvious reasons.
That's incorrect. It's not only perfectly acceptable, but absolutely vital, to pay someone for their services (incl a customer) for assisting with an existential threat against the corporation.
Any counsel or HR who would draft a corporate ethics rule that wouldn't allow for a bug bounty to be paid out on a massive vulnerability, merely because the person was "a potential customer", should be immediately replaced.