I do security audits and agree completely. My biggest issue is that the researcher is working for free. If nothing is found you just burnt a few weeks, if something is found the payout is usually only a couple grand.
If people enjoy doing it, or it makes sense in their currency or situation, awesome. The payouts don't get me excited though.
That's the market though. People who think it's too cheap don't play the game, people who think it's good money do.
In my country, getting paid 15k dollars would mean more than a years worth of sallary of a big infosec company. So it makes complete sense to go in for bug bounties, even if it's "low" payout, or if you spend a lot of time to get one.
Like you said, that's our market, but when working on a global scale, you have to consider pretty much everyone.
If people enjoy doing it, or it makes sense in their currency or situation, awesome. The payouts don't get me excited though.
That's the market though. People who think it's too cheap don't play the game, people who think it's good money do.