Earlier quoted context omitted.
Totally agree with your perspective here. There's security research and there's bug prospecting. Both have streaks of narcissists and showboaters but the latter seems to be thick with them. (edit: to clarify b/c this can easily be interpreted otherwise, I'm not calling the writer of this article either of those. The headline is a bit of cheap clickbait but the article is a good walkthrough of their mindset)
> There's security research and there's bug prospecting. If the end result of your work isn't a whitepaper or something similar from which others can learn, then you can call your work "security research". Bug bounty programs are mainly targeted at bug prospectors. > Both have streaks of narcissists and showboaters but the latter seems to be thick with them. Thank god for that. Blog posts like the one this thread is…
Further: this idea that "research" is something we have to valorize, and that you have to meet a public interest threshold to be worthy of it, is itself a standard to which the real world does not adhere. There are lots of different kinds of "research" out there; there are researchers who look for cures for cancer, and there are "researchers" who maintain stacks of index cards full of competitive market intelligence gleaned from press releases. The term "researcher" is about the kind of work you do, not the use to which it's put.
Maybe I'm just old and not keeping up with what the kids these days are saying, but I don't think "bug prospector" is a thing.