You know who can’t afford to ban security researchers? Companies & govs who need to know about bugs researchers find, that’s who. Microsoft, which receives over 200,000 non-spam e-mail messages a year, made it a priority to improve relations with hackers. Bans make no sense.
This tweet is unavailable
6
18
3
96
Replying to @k8em0
Back when I was at a large FinTech, we ran our own BB and only considered banning a researcher once, and that was because they went way beyond scope. They got a warning instead for the very reason you cite, we wanted the reports, and bans are only for criminal behavior.

Jan 1, 2020 Ā· 12:25 PM UTC

2