TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ask HN: How to price a responsibly-disclosed bug bounty?

4 pointsby seancolemanabout 4 years ago
I&#x27;m consulting with a small, bootstrapped company, and a security researcher responsibly disclosed an extremely serious issue that leaked root database credentials. Based on the vulnerability, I doubt this researcher spent a ton of time discovering the exploit, but the value to the company is (obviously) tremendous.<p>I want to formally recommend a reward amount, but I know the company doesn&#x27;t have much free cash. There is no bug bounty program in place. How do you go about thinking through pricing, especially for a non-BigCo? Thanks!

1 comment

mtmailabout 4 years ago
<a href="https:&#x2F;&#x2F;docs.hackerone.com&#x2F;programs&#x2F;bounty-tables.html" rel="nofollow">https:&#x2F;&#x2F;docs.hackerone.com&#x2F;programs&#x2F;bounty-tables.html</a><p>The large amounts you read about by big companies can hardly be matched my small companies. And rarely reflects the damage it could cause. Our maximum amount is US$1000 currently. We (<a href="https:&#x2F;&#x2F;opencagedata.com&#x2F;security-bounty" rel="nofollow">https:&#x2F;&#x2F;opencagedata.com&#x2F;security-bounty</a>) get regular reports where high or critical severity is claimed but maybe that&#x27;s only to get our attention. No report so far justified the full amount. We learned what is much appreciated is fast payout.<p>In <a href="https:&#x2F;&#x2F;blog.assetnote.io&#x2F;2020&#x2F;09&#x2F;15&#x2F;hacking-on-bug-bounties-for-four-years&#x2F;" rel="nofollow">https:&#x2F;&#x2F;blog.assetnote.io&#x2F;2020&#x2F;09&#x2F;15&#x2F;hacking-on-bug-bounties...</a> you see &#x27;full account takeover&#x27; listed as US$300 and &#x27;Critical issues on [redacted] (database credentials, entire application source code leaked and SQLi)&#x27; at US$800.