From the wikipedia page for Meltdown: "On 8 May 1995, a paper called "The Intel 80x86 Processor Architecture: Pitfalls for Secure Systems" published at the 1995 IEEE Symposium on Security and Privacy warned against a covert timing channel in the CPU cache and translation lookaside buffer (TLB). This analysis was performed under the auspices of the National Security Agency's Trusted Products Evaluation Program (TPEP)."
i.e. did they know even in 1995?
(NSA shortened the key as well so it wasn’t all bunnies and chocolate)
There should likely be a governing body that independently values an exploit and forces companies to pay
Like how the SEC’s whistleblower program works
Its completely broken to have corporations pinky promise not to sue you if you tell them and arbitrarily decide payouts if at all
Well I didn't know, until now. I saw the bug bounty page at Apple before, was dazzled by the numbers, and didn't think twice about approaching them if I found a bug. Now after this article I know better than to trust them to pay.
Is there a way to verify whether Zerodium might be advertising large payouts (for attention) and then offering much smaller payouts for the actual bugs?
It's pretty risky for Zerodium. There's nothing stopping a researcher from collecting a payout and then reporting the bug to the vendor.
Wouldn't the payout contract prohibit reporting to anyone else?
They might pay out over a long period of time for some guarantee that you'll play by their rules, though.
(Just guessing though.)
and tbh, it's probably the same answer for most providers these days.