As promised, Kim Dotcom starts payouts for Mega vulnerability reward program
thenextweb.com
thenextweb.com
Names, yes; $, no.
[1]: https://www.google.com/about/appsecurity/hall-of-fame/reward... [2]: https://www.facebook.com/whitehat/
http://www.nilsjuenemann.de/2012/12/news-about-googles-vulne...
To be clear - you think it's fine to cite the announcement of an undisclosed amount of money being paid to an undisclosed list of people as proof of their status as a good actor, yet you require concrete evidence that they are being deceptive for nefarious reasons to question his motives.
google == irresponsible ?
If you conduct any sort of business transaction with someone (and that's exactly what this is) a good business would assume that the transaction is private unless other arrangements are made with the other party. It's common sense and common courtesy.
If Mr. Dotcom asked first and then publicized the names, that's fine. If he made it a requirement of collecting the bounty, he's also within his rights. However, if he gave them the money and then disclosed their identities without asking them, it's would be an unprofessional thing to do. Not unforgivable, just unprofessional. Some people value privacy and anonymity. That's their prerogative.
http://www.chromium.org/Home/chromium-security/vulnerability...
Perhaps this is a new business model, replacing the traditional model of hiring expensive engineers to achieve secure software development? If this is true, then we should all move to this new model and the existing "talented engineers with expensive salaries" are simply overpaid.
I don't actually think this is true, but if it were, what would be wrong with it?
I think we should call this model open-soars, because it lets your software soar in the open sky above the competition.
Not saying that applies to you as such, but I see that sort of argument creep way too often.
In the long run, they're paying a reasonable amount of money for an army of security consultants to give the service a once-over. Smart!