- The severity of the exploit, which may be nearly the maximum theoretical possibility on a site like Facebook, aside from SQL injection or remote code execution
- The multiple months worth of unpaid sleepless nights Stephen Sclafani likely spent exploring countless dead-ends before finding this
- The fact that he beat black hats to the punch by discovering it first and thus saved Facebook and its users from millions, perhaps billions, of dollars worth of damages stemming from vague and mysterious causes over an indefinite period of time
- The billions of dollars Facebook regularly uninhibitedly spends to acquire a given startup
I feel that $20,000 is a bit low.
Oy.
Not that I am going to pretend that I know what the dollar value of Sclafani's time/effort should be, but I have a hard time believing that $20,000 is an insult. Just because he could get more money by exploiting the bug -- or showing others how to exploit it -- doesn't necessarily suggest to me that he should get paid more than he did.
In other words, if you can sell an item for $100k if you follow a set of laws (a government's, an organisation's, a community's, or your own), but you could sell the item without doing so for $500k, the item is still really only worth $100k (to you), but the (physical/societal/moral) danger involved in selling the item illegally that goes with it is not worth $400k to you.
Or, put another way, the item may be valued at $500k (to some potential buyer), but the legal buyer of the item is offering not to put you in danger in exchange for $400k.
Really? 20K is about two months of salary for a Facebook engineer. So even if he did spend months on this like you speculate (he didn't) it's still an industry-leading salary.