Earlier quoted context omitted.
Yes, that is actually worth it. This seems comparable to what a third party might pay. I have always wondered why the payouts are capped at the trillion dollar corps at such low figures. It appears like $75k max and MS and $100k max at Apple. Meanwhile shady 3rd party groups will pay you 10x that, won't they?
Cryptocurrency bug bounty programs perhaps have an advantage in that the risks of classes of bugs are often concrete, financially quantifiable, immediate, and catastrophic. A bad RCE in a mainstream OS could do untold damage to users, reputational damage to the company, and so on, but even if severe, those risks have to be estimated. But in this case, for example, it seems like the $2m bounty was for a bug that, if e…
That's a very solid point, as sad as it is.
I suppose the argument for OS makers to raise their rates might be that they are paying 10x below market rates, and the rates were set by the actual freaking market that exists.
If I was a congressional aide, I would definitely write something up about this when my boss was going to drag a Microsoft exec across the coals in public. I would imagine that billions in gov contracts are at risk for MS right now due to lax security. A $2M bug bounty could have prevented that.