sanitation@lemmy.today to Technology@lemmy.worldEnglish · 3 个月前AMD changes rules, denies researcher $10,000 bounty after taking 124 days to patch security flawwww.techspot.comexternal-linkmessage-square51linkfedilinkarrow-up1629arrow-down12
arrow-up1627arrow-down1external-linkAMD changes rules, denies researcher $10,000 bounty after taking 124 days to patch security flawwww.techspot.comsanitation@lemmy.today to Technology@lemmy.worldEnglish · 3 个月前message-square51linkfedilink
minus-squareITGuyLevi@programming.devlinkfedilinkEnglisharrow-up71arrow-down2·3 个月前A long time ago I felt like bug bounty programs would be an amazing way forward… Now I’m firmly in the camp of fuck it, sell it to the highest bidder.
minus-squareRememberTheApollo_@lemmy.worldlinkfedilinkEnglisharrow-up21arrow-down2·3 个月前The only issue with doing that is selling it to a nefarious party hurts the users and not really AMD. Or at least it isn’t hurting AMD anywhere near as much as it might hurt an innocent party.
minus-squareSculptor9157@sh.itjust.workslinkfedilinkEnglisharrow-up41·3 个月前And that is a risk AMD is willing to take.
minus-squareKnock_Knock_Lemmy_In@lemmy.worldlinkfedilinkEnglisharrow-up2·3 个月前Depends if the company has a history of honoring bounties or not.
A long time ago I felt like bug bounty programs would be an amazing way forward… Now I’m firmly in the camp of fuck it, sell it to the highest bidder.
The only issue with doing that is selling it to a nefarious party hurts the users and not really AMD. Or at least it isn’t hurting AMD anywhere near as much as it might hurt an innocent party.
And that is a risk AMD is willing to take.
Depends if the company has a history of honoring bounties or not.