The Case for a Government Bug Bounty ProgramOnce upon an Internet, a security researcher who discovered a vulnerability had very limited options for what to do with that information. He could send it to the vendor and hope someone cared enough to patch it; he could post it to a mailing list for all to see; or, if he had the right [...]
Source:
The Case for a Government Bug Bounty Program