3 ms·
Do you run a paid bug bounty program? I saw an interesting presentation from Finn.no about how they got most of their vulnerabilities through that, basically no
by hmottestad 2y ago
Do you run a paid bug bounty program? I saw an interesting presentation from Finn.no about how they got most of their vulnerabilities through that, basically none from their security.txt file, and a handful from people contacting the CISO on LinkedIn.
- toomuchtodo 2y agoWe do not, but I am prepared to pay a bug bounty out of my own compensation, for usual corp reasons. We don’t share this of course unfortunately, so I’m relying on good faith reporters to come forward at which point they get a Willy Wonka ticket if the vuln is legit (and not Burpsuite canned reports or the like). It’s…not ideal. You operate within the org constraints you must operate within.
- hmottestad 2y agoAre you the CISO?
- toomuchtodo 2y agoNo, but I believe it to be fair and proper to compensate someone for the value they provide in the event the org does not (and simply says thank you upon receipt of a genuine vulnerability report).