3 ms·
Don't waste your time and money on funding bug bounties or "getting audits done". Your staff will add another big security flaw just the next day, back to squar
by Rygian 9mo ago
Don't waste your time and money on funding bug bounties or "getting audits done". Your staff will add another big security flaw just the next day, back to square one.
Spend that money in reorganizing your management and training your staff so that everyone in your company is onboard with https://owasp.org/Top10/2025/A06_2025-Insecure_Design/ https://owasp.org/Top10/2025/A06_2025-Insecure_Design/ .
- staticassertion 9mo agoIf part of the problem was that no one was responding to a vulnerability report then a bug bounty program would potentially address that.
- liveoneggs 9mo agoyou just get spammed with the same three fake reports over and over
- staticassertion 9mo agoTriage is something that these services provide, exactly to deal with that.
- liveoneggs 9mo agogood try :)