TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: How to price a responsibly-disclosed bug bounty?

4 点作者 seancoleman大约 4 年前
I&#x27;m consulting with a small, bootstrapped company, and a security researcher responsibly disclosed an extremely serious issue that leaked root database credentials. Based on the vulnerability, I doubt this researcher spent a ton of time discovering the exploit, but the value to the company is (obviously) tremendous.<p>I want to formally recommend a reward amount, but I know the company doesn&#x27;t have much free cash. There is no bug bounty program in place. How do you go about thinking through pricing, especially for a non-BigCo? Thanks!

1 comment

mtmail大约 4 年前
<a href="https:&#x2F;&#x2F;docs.hackerone.com&#x2F;programs&#x2F;bounty-tables.html" rel="nofollow">https:&#x2F;&#x2F;docs.hackerone.com&#x2F;programs&#x2F;bounty-tables.html</a><p>The large amounts you read about by big companies can hardly be matched my small companies. And rarely reflects the damage it could cause. Our maximum amount is US$1000 currently. We (<a href="https:&#x2F;&#x2F;opencagedata.com&#x2F;security-bounty" rel="nofollow">https:&#x2F;&#x2F;opencagedata.com&#x2F;security-bounty</a>) get regular reports where high or critical severity is claimed but maybe that&#x27;s only to get our attention. No report so far justified the full amount. We learned what is much appreciated is fast payout.<p>In <a href="https:&#x2F;&#x2F;blog.assetnote.io&#x2F;2020&#x2F;09&#x2F;15&#x2F;hacking-on-bug-bounties-for-four-years&#x2F;" rel="nofollow">https:&#x2F;&#x2F;blog.assetnote.io&#x2F;2020&#x2F;09&#x2F;15&#x2F;hacking-on-bug-bounties...</a> you see &#x27;full account takeover&#x27; listed as US$300 and &#x27;Critical issues on [redacted] (database credentials, entire application source code leaked and SQLi)&#x27; at US$800.