The Repudiation Problem In Bug Bounties

Mohit Kumar rants about bug bounty programs.  Done correctly, a bug bounty can be a great incentive for finding problems with software.  But there is a repudiation problem inherent in the system.  Here's a stylized example to show the problem.  Suppose we have a company X, which releases a software product.  Company X's management decides…