Aside from following the law, companies should also take care that their bug bounty payments are adhering to responsible corporate policies that define what constitutes a legit payment and what constitutes extortion.
Cybersecurity experts and digital rights organizations say that the high court’s future ruling will determine whether bug hunters and pen testers could be charged if their research into systems is deemed excessive, even if the actions are intended to be ethical.