Bug Bounty Programs Are Being Used to Buy Silence
Schneier on Security 2020-04-03
Summary:
Investigative report on how commercial bug-bounty programs like HackerOne, Bugcrowd, and SynAck are being used to silence researchers: Used properly, bug bounty platforms connect security researchers with organizations wanting extra scrutiny. In exchange for reporting a security flaw, the researcher receives payment (a bounty) as a thank you for doing the right thing. However, CSO's investigation shows that the bug...
Link:
https://www.schneier.com/blog/archives/2020/04/bug_bounty_prog.htmlFrom feeds:
Berkman Center Community - Test » Schneier on SecurityGudgeon and gist » Schneier on Security