I would rather see more transparency once you are a reporter than shinier leaderboards. It is extremely frustrating to spend a week reverse engineering a vulnerability in an opaque cloud service only to be told it was a known issue (but private), won’t be fixed (but is within 48 hours), and that you don’t qualify for any compensation. I would like to see private issues shared with reporters when they are independentl…
This kind of issue is rampant and opaque among bug bounty programs.
IMO if a company says a bug is a wontfix, that's an immediate moral justification for public disclosure.
If they say it's a known issue, they don't give a timeline of when it will be fixed, and it's still not fixed in a week, that's also moral justification for public disclosure. If multiple people have reported the same vulnerability, there is a high likelihood that the bug is known by even more people. Bugs that are not hastily addressed are wasting participants in your bug bounty's time.
Companies with bug bounty programs need to treat security researchers with more respect, and when they don't the moral imperative shifts towards public disclosure so that others are warned that vulnerabilities exist and are not being addressed. Too many companies set up a bug bounty program as a box checking exercise and then have a lackadaisical attitude about addressing reports.
I found a pretty obvious XSS on Tesla's website. Submitted through bugcrowd and got no information besides "marked as duplicate". Publicly disclosed, bugcrowd temporarily suspended me for disclosing, but it was fixed within a week. Nothing lights a fire under people's asses like airing their dirty laundry. If they had told me "we are working on a fix and expect it to be live in 3 weeks" I would have respected that and held off on disclosure.