15k? Heartbleed bug worth more like $1M
run-node.com
run-node.com
It's quite easy -- and probably completely ineffective -- to come out and say someone should pay this man one million dollars. In my opinion, it's a lot more helpful to shell out some money yourself, at least if you think other people are obligated to do so.
I don't mean to say that this guy should just "shut up and pay up" -- not at all. My point is that it's often a lot more effective to, when something needs to be done, do 1% of what needs to be done, instead of asking "other people" to do 100% of it. If we all do the latter, nothing gets done, and if only 100 people do the former, it's done.
Seems like people don't care enough to put up the cash. Why?
There are data breach insurance policies for sale. Why aren't these insurance companies putting up bug bounties for responsibly disclosed vulnerabilities? Is there a market gap here?