• Matt@lemmy.ml
    link
    fedilink
    English
    arrow-up
    4
    ·
    2 days ago

    …that will pay those who responsibly disclose security vulnerabilities that affect fediverse apps and services.

    If it is straight to the project, then I’m all for it. Otherwise, it seems sus.

    • PhilipTheBucket@ponder.cat
      link
      fedilink
      English
      arrow-up
      3
      ·
      edit-2
      2 days ago

      It is to the person who discovers the vulnerability. That’s fairly normal… how would giving it to someone else motivate the result they’re trying to get?