The author puts forward the (unsubstantiated) assertion that Microsoft paid context to search for WebGL security issues. Not that this is a bad thing (more eyes = better security long term) but it would have been good of Context to provide this information in their recent writeups.