57
you are viewing a single comment's thread
view the rest of the comments
[-] Telorand@reddthat.com 15 points 18 hours ago* (last edited 18 hours ago)

why anyone would trust these companies to pay out

AFAIK, they historically have

why anyone would help them fix their problems at this point

They're not "helping," they're trying to get paid by finding exploits legally, rather than using them illegally. And if someone is particularly good, it can be lucrative work. It's historically been a mutually beneficial arrangement, so it's ironic if M$lop thinks they can cut out human researchers (ostensibly swapping them for AI agents) and still maintain a secure codebase.

To me, this is M$lop trying to cut costs from the wrong thing; may they get what they deserve.

ETA: and if they make it impossible to make a living at reporting exploits legally, there's really only one option left to make a living...

[-] grey_maniac@lemmy.ca 7 points 18 hours ago

ETA? In my life experience that means estimated time to arrival. What do you mean in this context?

[-] Zoop@beehaw.org 1 points 11 hours ago

In this context, it means 'edited to add'

[-] avguser@lemmy.world 7 points 17 hours ago
[-] redsand@infosec.pub 2 points 13 hours ago

Selling exploits is more of a legal gray area depending on jurisdiction and licensing.

this post was submitted on 27 May 2026
57 points (96.7% liked)

cybersecurity

6178 readers
113 users here now

An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!

Community Rules

Enjoy!

founded 3 years ago
MODERATORS