2 ms·
Bugcrowd is no different. The folks doing Triage often don’t comprehend even simple security issues. I’m convinced it’s largely designed to keep people from go
by wepple 2y ago
Bugcrowd is no different. The folks doing Triage often don’t comprehend even simple security issues.
I’m convinced it’s largely designed to keep people from going full disclosure rather than actually getting bugs fixed.
- bawolff 2y agoAs someone who worked on the other side (i.e. at a previous job i handled incoming bug bounty reports) a big part of why we used H1 is that it can be exhausting dealing with reporters. Often the reports are non sensical. Even the one's that are real, often there will be very minor issues that the reporter feels should get top payout. Sometimes reporters are very demanding and rude. At the same time you can't just throw out the crazy reports, because sometimes the crazy looking emails actually have the legit vulns. H1 exists because once you start offering money the crazies start to show up, and its a lot of work to keep up with it. (That's not to say that you are entirely wrong either. I am sure some less scrupolous companies do have that goal. However a lot of the time its simply that the vuln has low impact so its low priority. Depending on how the company is managed, often there is dysfunction where the security team lacks the ability to get things prioritized)
- wepple 2y agoOh yeah, I’d absolutely not want to have a raw unfiltered inbound bug bounty and be first line of triage, so paying H1 or Bugcrowd is the way to go. But you’re also paying them to make sure the serious bugs absolutely do get to you, and if researchers give up, you’re not getting the value you need. I suspect the problem is that the type of folks who are prepared to do front-line triage which is most commonly large volumes of nonsense and a few mediocre bugs, are early career security folks who can’t easily spot a really serious P0 and a researcher who clearly knows what they’re talking about.