5 ms·
"It's not a small sum, but if we had gone through the normal process of hiring an outside firm to do a security audit and vulnerability assessment, which is wha
by Dystopian 10y ago
"It's not a small sum, but if we had gone through the normal process of hiring an outside firm to do a security audit and vulnerability assessment, which is what we usually do, it would have cost us more than $1 million," ...
It seems like a a pretty small sum to me. They paid out amount between $100-15000 for the bounties with a total of $75000. Gauging that one of the bounties at $15K sucked up around 20% of the overall budget and there were 137 other reports - it's literally the equivalent of paying outsourced-ODesk rates for security testing in time/value.
What reason would anyone have for wanting to actively participate (not just poke-around like I'm sure quite a few employed professionals did) vs selling the exploits off on the dark web or just working in security for a company that pays a reasonable rate?
- k-mcgrady 10y ago>> "What reason would anyone have for wanting to actively participate (not just poke-around like I'm sure quite a few employed professionals did) vs selling the exploits off on the dark web or just working in security for a company that pays a reasonable rate?" The answer the your first alternative is pretty obvious: morals. That and not wanting to do jail time. To the second alternative I'm sure the people participating mostly have jobs or other commitments are are doing it for reasons other than the money.
- ddworken 10y agoYeah exactly. I certainly was in it for more than the money and would have happily worked on it even if there were no bounties.
- x5n1 10y agoUsually they use this as a recruiting tool.
- imglorp 10y agoThe kids will find some low hanging fruit for cheap. It's a quick smoke test. After they get done fixing those, one would hope they still hire the pros.