Funny, I find it interesting that they want to pay a bugbounty even though nobody asked for it. But I guess paying hush money is just cheaper than having to seriously fix the issue.
They did fix the issue, though.
And if these guys were to go though the NDA route, The company may choose just not to fix it at all, and tell these researchers to be quiet about it. And you'd never know there was such a exploit ever.
They objected to having to sign an NDA, when there was no clear incentive to legally bind themselves in that manner.
NDA? HackerOne? Personal Information with Identity and Credit History Verification, Cookies and Disclosure Agreements, and 3rd party terms? Why is it at all "interesting" that a security researcher is not interested in giving all of up in order to tell CrowdStrike that their core product is broken in a way that is completely inimical to its mission purpose?
"Can you notify my lawyer by FAX, please? And can you get the document notarized first? Kthxbai".