Correct me if I am wrong, but don’t these bounties help dissuade people from selling these security vulnerabilities to malicious actors?
This smells like a “We have AI for that now” decision from way up top. The kind of level that is so high it has absolutely no idea about how any of it works, but thinks in gains.
Great way to see them get released publicly on GitHub
I have a feeling that the people with the skills to discover 100k exploits before anyone else does will get that 100k either way.
If it’s that serious (like a VM escape for example) and Intel (or any software/hardware vendor affected) doesn’t wanna pay, there are MANY interested parties that would happily buy it from you.
Isn’t this just the natural consequence of a flood of new bug reports generated by ai, with little skill required?
They saw how good Microsofts mistreatment of the bug hunter community went down and felt they wanted a piece of that sweet online rage
Oh so I have no reason except the goodness of my heart to disclose security flaws? Cool lemme see how many pizzas I can buy with that aaaaaaand, oh…




