I think most of the people saying "rip off" consider token $1k checks "ripping people off," considering implementing it correctly would require hiring talented engineers with expensive salaries. Given the giant holes punched in the original security implementation pretty much immediately after launch, he seems to have skimped on engineering talent preferring to instead pay these small bounties.
Sometimes even the smartest and most expensive engineers fail to find things 14 year old kids in their poster-laden bedrooms seem to be able to find these days... Google, Facebook and other tech companies seem to see the value in having a bounty program for security issues and bugs as well and by the looks of it, Dotcom is offering the same reward amounts as Google and Facebook are offering, so I guess by your logic Google and Facebook (two companies with larger amounts of money and smart engineering hires) are ripping people off as well? You are forgetting that Dotcom has to hire competent engineers to fix the reported issues, I doubt a lot of people finding the bugs and vulnerabilities are providing code samples and fixes to Dotcom. They're merely finding the holes and it's up to Mega to get their team of engineers to fix the issues.
> considering implementing it correctly would require hiring talented engineers with expensive salaries
Perhaps this is a new business model, replacing the traditional model of hiring expensive engineers to achieve secure software development? If this is true, then we should all move to this new model and the existing "talented engineers with expensive salaries" are simply overpaid.
I don't actually think this is true, but if it were, what would be wrong with it?
You could also provide all the source to your program to your customers, so they could see and modify it. With this, every customer who has the time and inclination to report and help with the resolution of a problem is like a new pair of eyes looking for bugs. It could be said that with enough pairs of eyes, all bugs seem eye-poppingly obvious.
I think we should call this model open-soars, because it lets your software soar in the open sky above the competition.