4 ms·
was going to say similar things. A bug bounty has value -- and its effectively to incentivise someone who finds a vulnerability to tell you, rather than exploit
by splynch 6y ago
was going to say similar things. A bug bounty has value -- and its effectively to incentivise someone who finds a vulnerability to tell you, rather than exploit it or sell it to someone who will exploit it. Its the same as a pen test.
I dont want to name companies and start a war, but the industry is moving in a dangerous direction with some of the other options -- there are companies offering pen testing where those companies have no full time employees. They post the scope, and their registered users can sign in, take the work, and deliver it. Quality is all over the place. And things like confidentiality, data processing, etc, and any way to confirm a corporate entity adheres to their contractual obligations? Nonexistent.