• SoupBrick@pawb.social
    link
    fedilink
    English
    arrow-up
    35
    ·
    8 hours ago

    Correct me if I am wrong, but don’t these bounties help dissuade people from selling these security vulnerabilities to malicious actors?

  • saltesc@lemmy.world
    link
    fedilink
    English
    arrow-up
    40
    ·
    edit-2
    9 hours ago

    This smells like a “We have AI for that now” decision from way up top. The kind of level that is so high it has absolutely no idea about how any of it works, but thinks in gains.

  • Zer0_F0x@lemmy.world
    link
    fedilink
    English
    arrow-up
    17
    ·
    9 hours ago

    I have a feeling that the people with the skills to discover 100k exploits before anyone else does will get that 100k either way.

    If it’s that serious (like a VM escape for example) and Intel (or any software/hardware vendor affected) doesn’t wanna pay, there are MANY interested parties that would happily buy it from you.

  • Droechai@piefed.blahaj.zone
    link
    fedilink
    English
    arrow-up
    15
    ·
    9 hours ago

    They saw how good Microsofts mistreatment of the bug hunter community went down and felt they wanted a piece of that sweet online rage

  • Stern@lemmy.world
    link
    fedilink
    English
    arrow-up
    7
    ·
    9 hours ago

    Oh so I have no reason except the goodness of my heart to disclose security flaws? Cool lemme see how many pizzas I can buy with that aaaaaaand, oh…

  • AA5B@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    8 hours ago

    Isn’t this just the natural consequence of a flood of new bug reports generated by ai, with little skill required?