I’m convinced it’s largely designed to keep people from going full disclosure rather than actually getting bugs fixed.
I’m convinced it’s largely designed to keep people from going full disclosure rather than actually getting bugs fixed.
H1 exists because once you start offering money the crazies start to show up, and its a lot of work to keep up with it.
(That's not to say that you are entirely wrong either. I am sure some less scrupolous companies do have that goal. However a lot of the time its simply that the vuln has low impact so its low priority. Depending on how the company is managed, often there is dysfunction where the security team lacks the ability to get things prioritized)
But you’re also paying them to make sure the serious bugs absolutely do get to you, and if researchers give up, you’re not getting the value you need.
I suspect the problem is that the type of folks who are prepared to do front-line triage which is most commonly large volumes of nonsense and a few mediocre bugs, are early career security folks who can’t easily spot a really serious P0 and a researcher who clearly knows what they’re talking about.