It's also complying with tax and employment laws in the country the hacker is in, to the satisfaction of your legal and finance teams.
Sure, in western-style legal systems you can call them a contractor and they can pay their own tax. Just don't employ them full time for long enough to trigger 'sham contract' rules that would make them employees.
But your corporate legal team doesn't have anyone trained and licensed to give advice on Tajikistan tax and employment law, so they can't approve this proposed contract without hiring an outside legal expert. And of course all suppliers, regardless of country, must agree to our anti-slave-labour policy which permits audits of...
One might say "skip that nonsense, just send the money" - but the larger the company, the more their in-house infosec becomes a load of uptight squares who love compliance and audit. And the kind of companies that can pay out five-figure bounties tend to be pretty large.
CEO: "I'm not sure I like the idea of us inviting people to hack us - or paying a 'bounty' to hackers holding a knife to our throat. Will they at least agree to a binding NDA and terms of engagement, in advance?"
CISO: "No, they won't."
CEO: "Well, at least if the hackers are in poor countries, a $500 payout for a critical bug will be plenty, right?"
CISO: "No, critical issues will be 10-100x that"
CEO: "Well will the average quality of these reports better than those we get from our hired pentesters?"
CISO: "On average these will be the lowest quality reports you've ever seen. But 0.1% might be gold. Oh, and I need to hire 3 more guys to sift through these terrible reports. Also our sifters might miss the gold."
CEO: "Oh. Well at least we won't be breaking the law though, right?"
CISO: "Uh, about that..."
At this point, I think most crypto investors in Italy will just evade taxes altogether.
And if you've got taxes like that on earned income - shouldn't people with unearned income pay just as much? If your tax on investment gains is too small, you end up with an economy where the salaried worker renting a house pays more tax than their landlord, who owns ten houses.
HN really is living in their own bubble.
Yes it does.
> You can gamble with it, but it doesn't let you own or send it.
You can deposit (receive) and withdraw (send) cryptocurrencies there.
"Owning" is a matter at the private key level which of course you use a self-hosted wallet for "true" ownership. But no argument was made on ownership.
My point still stands that Revolut is a bank that allows cryptocurrencies.
The US is not the entire world.
Revolut has major banking licenses in Europe, UK and Mexico. That doesn't mean it is not bank.
Wells Fargo does not operate in the UK, but it is still a major bank in the US and it is still a bank.
Royal Bank of Scotland (RBS) is a bank in the UK. Just because it doesn't operate in the US, does not mean it isn't a bank.
> Don't be gullible and believe blindly what the marketing departments tell you.
Revolut is still a major bank even if they don't operate in the US (yet).
No better than recalling a wrong bank transfer or Zelle transaction.
But anyway, the point is that it tells you every single time you send a transfer that way to be careful, because you can't undo a transfer after it's been sent. I'm assuming it's the same for most methods of bank transfer? I mean, debit transactions are surely a different beast.