Security researchers rewarded $12.50 voucher to buy Yahoo T-shirt
grahamcluley.com
grahamcluley.com
Funny how actual cash evokes different reactions.
And then they end up looking like jerks.
Really puts the $12.50 in company store credit into perspective.
With that being said, $12.50 is $12.50 more than PayPal's. I don't know anyone who has reported a vulnerability to PayPal that has actually received a reward.
Edit: this reminds me of the "eBay goodies" offered to researcher Neal Poole in return for delaying disclosure of a vulnerability [https://nealpoole.com/blog/2013/03/bad-changes-to-ebays-resp...]. I would probably not have remembered that story if not for that "eBay goodies" line, just as I probably won't forget this story thanks to the screenshot of Yahoo-branded socks in the company store.
I believe that not paying is better than paying little, because if you don't pay I can at least consider that you owe me one. Giving me a pittance removes the obligation from you for almost nothing. Even though this isn't very applicable to companies, I think that's the reason why we consider it insulting.
I think the problem with Yahoo's response is that it looks like they are actively being cheapskates. Almost universally, cheap is worse than no-money-involved. A "thank you" might be appreciated, a reasonable monetary reward will probably be appreciated, and even sending some free swag might read as a warm gesture, but offering a $12 store credit pretty explicitly says "I value this very little."
Is this worse than the many companies that have never given anything to any reporter?
Besides, I suspect working as freelance l33t hacker is more profitable and gets you laid at parties.
It's great to see that we came to this point.
$12.50 seems insulting. "Oh, your time is worth $12.50 to us, but thanks for disclosing a huge XSS issue."