Bug bounties work well for publically accessible systems, e.g. a site's web service. As a result, many of the more visible break-ins occur through phishing or spear-phishing and combine social engineering with malware as well as classical intrusion techniques from within the network perimeter.
Yeah, let's just equate criminal behavior with doing people a service, that's going to reflect well on people in IT.
No worse than us being unable to take an extremely obvious joke as a joke, and feeling the need to respond to it as if it wasn't meant completely in jest.
Joking is against the HN guidelines. I was completely serious.