Earlier quoted context omitted.
Full disclosure is always responsible, even if the vendor is not notified in advance.
This is a part of our industry I do not follow beyond headlines. A lot of those headlines are about hackers trying to be responsible getting screwed out of supposed bounties that to my mind already appear quite small. Also responsible companies doing very little to quickly close them. Does anyone have any insight into how the market for vulnerabilities operates? Is there is a significant disparity in price between of…
Apple's published rates are high (up to $1M), but in practice they pay a lot lower.