The difference is that you pay her either way. HackerOne doesn't. If HackerOne wants the advantages of paid employees then they need to pay for employees and not mask it as a bug bounty program.
If it’s not a real vulnerability then why would it matter if she publicised it?
Or, is it actually a real vulnerability but you don’t want to admit it because she (the security consultant) is getting paid per vulnerability found?
Unless the company is lying and it IS a real vulnerability, writing an article about it seems harmless to me.
OFC that if I planned on writing an article I'd be open about it beforehand, but that feels like a courtesy and not an obligation unless an NDA is involved.
Disclaimer: I don't work in security so this is purely curiosity.
Like OP wrote in this thread, it either is a vulnerability or it's not. In the latter case, just assume it's the cost of doing business and people will write "bad" things about your product?
> Please note that we will not consent to disclose reports if they have been marked out-of-scope or inapplicable, or where Valve has not taken a specific corrective action / mitigation.
> Valve embraces transparency in our security. We will generally disclose the details of vulnerabilities found, upon request.