
Unpopular Opinion: Companies Offering "Swag Only" or "Hall of Fame" for Critical Vulnerabilities Should Be Publicly Shamed
bug_bountycybersecurityvulnerability_disclosureethical_hackingswagmonetary_rewardsFortune_500industry_standards
A bug bounty hunter with one year of experience expresses frustration toward Fortune 500 companies that fix critical P1/P2 vulnerabilities (such as SQLi and RCE) by offering only t-shirts as rewards. They argue that companies with a budget for a security team should also have a budget for monetary rewards and believe that accepting "swag" devalues the work in the industry. They plan to automatically ignore any program that does not pay in cash and wonder whether they are being too demanding or if the industry is being exploited.