Comment on AMD changes rules, denies researcher $10,000 bounty after taking 124 days to patch security flaw
Australis13@fedia.io 2 days ago
This is how you create people like Nightmare Eclipse.
These people are going out of their way to responsibly disclose vulnerabilites to the bug bounty programs and being treated poorly as a result. Granted, AMD technically didn't have to pay since it was a MITM attack, but they could have at least handled the whole interaction better.
Onomatopoeia@lemmy.cafe 2 days ago
And simply paid they guy out of appreciation.
I generally support the model we’ve had for. Bug disclosure - it’s about preventing zero days which protects the users of these products.
But for AMD stuff now, go ahead and sell your discoveries, let the zero-days ruin AMDs marketing.