Asking people to pay to submit bugs would start a firestorm of internet drama about asking people to do free work for the company and pay for the privilege. It doesn’t matter if the program actually paid out.
If they got even one report closed incorrectly we would never hear the end of it.
At this point there isn't an excuse.
[0] https://www.usdc.com/learn/fiat-backed-vs-algorithmic-stable...
I don't really need to convince you. I just look at how it's being tested and which companies are using it today.
But the main point I'm bringing is that stablecoins exist and the most trusted one USDC is used today by hundreds of companies after going under regulatory scrutiny for years and it can be used to send money.
You just said: "I don't know how to differentiate them." and I replied with a clear distinction with evidence comparing the two.
> Crypto shills were saying the same things about UST before its collapse...
Just like with all untested tech, there will always be alternatives out there with their fans, VCs and shills who have a vested interest and UST was one of them and when tested, some will fail which is expected.
So your answer is to paint all with a broad brush and to then dismissing them because one based on an untested technology failed doesn't make much sense.
In those case you already lose time, but in the future you would also lose money.
Unfortunately you don't know how a company will react before submitting, especially if it's a small one.
I'm not trying to suggest they _need_ to implement it. Like I said, closing it is reasonable. Completely aside from any other considerations, one could just decide that they don't feel like dealing with it. But there are other options.
Hell, use blockchain for it to keep the ledger valid an hard to corrupt.
https://news.ycombinator.com/item?id=47793926 Laravel raised money and now injects ads directly into your agent
(A click bait headline from a critic but this seems inevitable.)
For those who encounter bugs as part of their employment, they'd now need to convince their employer to fork over money up front. For most employers, getting them to spend even insignificant money is like pulling teeth.
But even for the self-employed or hobbyists, gambling real money on "are they going to be a jerk about my exploit report". No offense towards Turso, but the bulk of software firms are TERRIBLE about handling reports like that. Many already have unstated policies of screwing people out of deserved bug bounties at every step.
To submit such reports today already requires you to accept that your work is statistically, just going to be a bunch of free labour that you gave away for the betterment of the product's users. Adding a cash fee just further deters submissions, especially once people haven't gotten their money back a few times. (Consider how many "AI detection tools" are themselves incredibly unreliable machine learning or sometimes even LLM systems)
I'd say closing a program which doesn't work anymore is a better idea.
If you can think of something that isn't solved by one of those two mechanisms, I'd be interested in hearing them enumerated.
If they have to pay for reviewer time for each of 1000 reports, then the scheme stops being viable.
Sounds a bit weird for an open source project but I can tell you that the one company I worked at that used Phabricator did pay (and they definitely wouldn't have otherwise) so I think it's a viable strategy. Plus it makes you immune to slop!
On the other hand they did shut down a year or so ago though. Didn't say why.
It's even possible to directly link this to maintainers/employees - if you can review 10 such AI/real things per hour (likely more if it's AI slop that's easy to detect), you're generating another revenue stream. Now, I have no idea if these guys are based in SF Bay or a 3rd world country with low COL but as an "add on", $100 an hour isn't too shabby (and can be on the "low end" if one's good at spotting AI crap.)
Side note, isn't it possible to have some way to verify if the "vulns" are actual vulns or not? ...Heck why not throw an LLM at it, powered by a single $10 submission fee?
AI is really throwing a wrench in the economics of software development, isn’t it?