3 ms·
This is a bit disingenuous. It's almost impossible to measure the output of the other teams/consultants because their reports are never made public. I wish tha
by awirth 10y ago
This is a bit disingenuous. It's almost impossible to measure the output of the other teams/consultants because their reports are never made public.
I wish that we had more opportunities available for researchers to do the work that Tavis is doing. He is very very good and highly productive, but he's not somehow orders of magnitude better at his research than others. The thing that makes him unique is that Google is paying him a full-time salary just to find bugs and post them publicly. He doesn't have to worry about only targeting stuff in bug bounty scope or working on executive-targeted write-ups and consultation reports to make ends meet.
Basically, he gets paid to spend all day, every day, finding bugs and documenting them for people to see. We need more people in those sorts of positions, but only Google is really able to bankroll it.
- dsacco 10y agoYou make a fair point, but I don't think it's an argument against what I'm saying. If for no other reason than what you stated about being paid for such open goals, he certainly is more productive than most consulting teams. And given his practice and experience at that sort of productivity, he's likely more capable as well. I agree that security consulting results should be more open, but incentives are not really aligned for that to be the case.