• Matt@lemmy.ml
    link
    fedilink
    English
    arrow-up
    4
    ·
    2 months ago

    …that will pay those who responsibly disclose security vulnerabilities that affect fediverse apps and services.

    If it is straight to the project, then I’m all for it. Otherwise, it seems sus.

    • PhilipTheBucket@ponder.cat
      link
      fedilink
      English
      arrow-up
      3
      ·
      edit-2
      2 months ago

      It is to the person who discovers the vulnerability. That’s fairly normal… how would giving it to someone else motivate the result they’re trying to get?