Earlier quoted context omitted.
> you can hire there lies the difference, duh.
And what about the hundreds of NPM dependencies in VS Code no one reviews? Or the the thousands of brew packages that are blindly merged unsigned by 800 people with access? Who pays to give a white hat as much freedom to find supply chain attack vectors here? Who gets consent from every random student whose code, if compromised, would compromise every major company? We have created a massive mess, and I don't know th…
> We are going to need unpaid volunteers, and a lot of them.
that's absolutely orthogonal to the question at hand, it's not a matter of paid or unpaid, neither being volunteer or not: it's a matter of consent.
if you don't sought consent beforehand either via a contract relationship or a sponsored bug hunt program or the likes, you're a racketeer, not a white hat, and you should (and will) be treated as such.