> If you pay out for weak, stuck-in-process bugs, you create incentives that redirect programmer time to those weak bugs and away from more significant bugs; as angry as you can reasonably be about a malicious app being able to snarf your contacts, if you're rational, you're a lot more concerned about memory corruption flaws, which is what you really want people spending their time on.
I don't understand how this isn't already reflected in bug bounty pricing tiers? Like, if I access your contacts, I get $x, but if I can access all your photos, I get $xx. As a user, I couldn't care less for how my data got accessed, whether it's a logic bug or memory corruption…