Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Companies sometimes reward their employees with important bug fixes. When I worked on a big dev team, we'd even decide what were the most important fixes and give people a special 5k bonus or something.

But they weren't security issues necessarily. I never thought about it, fixing a huge performance issue is big. A security fix that gets caught early makes no noise so you just don't know how important it would have been. We also once had a really terrible bug that lead to lots of customers getting effectively attacked.



> Companies sometimes reward their employees with important bug fixes.

Potentially creates a misaligned incentive to intentionally hide bugs in the code you write so that later you can fix it and get the bounty.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: