3 ms·
These programs are great in the sense that companies are starting to accept security research and appreciate responsible disclosure instead of non/full disclos
by a1a 10y ago
These programs are great in the sense that companies are starting to accept security research and appreciate responsible disclosure instead of non/full disclosure.
However, and I know this is not a popular opinion and that most people argue they do it "just for fun". But in my mind the "just for fun" argument is nothing more than an excuse for letting large corporations* use you. Seriously, swag? Your hourly salary is minimal wage. What about all the time you spend studying? You should get payed like everyone else. Even if you really think it is that much fun, why wouldn't you want to be able to make a living out of it? Your knowledge should be (and are!) valuable.
I don't really have a solution. Maybe time is the answer. Globalization does not make it easier as the bounties are quite large from the perspective of some countries.
What do you guys think? I think it is time we start valuing our knowledge. No one will do it for us.
* If it is a start-up, non-profit, or a corporation you believe makes the world a better place the situation is different, obviously. Nothing wrong with volunteering your knowledge.
- audleman 10y agoCyber security is a paying profession and I don't think bug bounties undercut that. A company that's not willing to pay and wants to put in place a bug bounty will get what it pays for, which is a mystery to them and us. Others will pay. Fin Tech companies, for instance, have regulations that require a professional audit every year. We recently paid out over $25k for one of them (and it was worth it, their guys found some extremely subtle vulnerabilities). Also hacking on sites for fun and profit is fun and something some people like to do in their spare time. So some people are gonna do it no matter what.