Just saw the announcement. They're offering cash for vulns found in their API and web app.
My first thought: is this a genuine step towards hardening, or just PR cleanup after that token leak last month? Throwing money at researchers doesn't magically fix a broken SDLC.
If their internal security was any good, they wouldn't *need* a public bounty to catch basic stuff. Real security is boring: proper audit trails, secret management, regular patching. Not a flashy program you can put in a blog post.
I'll believe it when I see the first few payout reports. If they're just catching low-hanging XSS, it's theater. If they're actually paying out for critical auth bypass or data leaks, maybe they're serious. Color me skeptical.
If it ain't broke, don't 'upgrade' it.