5 ms·
I think suspicion of bug bounties even from organizations who would clearly benefit the nost from doing them right are well founded and you are over simplifying
by klingoff 2y ago
I think suspicion of bug bounties even from organizations who would clearly benefit the nost from doing them right are well founded and you are over simplifying the situation.
Every organization includes a mess of situations where the overall best interest of the organization no longer comes through. Groups and individuals don't want to admit mistakes both personal and in wider senses and have alliances, competitions, team and organizational loyalty that twists their behavior.
A lot of organizations know they would benefit from having a proper whistle blower program and then proceed to crucify the first person who uses it.
- tptacek 2y agoBug bounty programs aren't whistleblower programs.
- throwaway48476 2y agoAP is saying they can suffer from the same corporate politics.
- tptacek 2y agoThat doesn't make sense, because bounty programs can't punish vulnerability researchers other than not awarding bounties, and whistleblower programs can punish whistleblowers. I got what that comment was trying to say, but, no.
- throwaway48476 2y agoIt becomes corporate politics when 'blame' is assigned to the team responsible for the bug.
- tptacek 2y agoThe preceding comment, I could follow. This one I cannot. But I think we're doing the same thing that's happening all over this thread, and trying to axiomatically derive how these programs work. I'm not doing that; I (like a lot of people) have direct knowledge of them. It's not much of a secret.
- klingoff 2y agoHuh? Whistleblower programs exist to defend them and fail to combat the problem, one that directly punishes would be like a bounty program that actually crafts the legal threats to security researchers.
- Moru 2y agoThat is being done too. Teenagers showing vulnerabilities in school systems have been prosecuted in Sweden... Needless to say, they didn't get much help with looking for holes after that so who knows how many security holes they still have.