Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> To recap our progress on these goals, here is a snapshot of what VRP has accomplished with the community over the past 10 years:

> Total bugs rewarded: 11,055

> Number of rewarded researchers: 2,022

So each person found an average of 5.5 bugs? That seems really high, no?



The distribution probably has a relatively small amount of people reporting a disproportionately large amount of the bugs.


This is very true. It's been a reality for a long time that the most successful (measured in $x rewarded) bug hunters sometimes have hundreds or even thousands of bugs submitted per year.

This way, they can capitalise on the fact that smaller security issues are much easier to find, especially if the bug hunter has expertise in the underlying framework.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: