
Adam Bacchus and Jon Bottarini -- Two Sides to a Bug Bounty: The Researcher and The Program
Om avsnittet
What does a bug bounty look like from both sides of the relationship? Adam Bacchus and Jon Bottarini of HackerOne compare the responsibilities of the program operator with the experience of the security researcher. They discuss safe-harbor language, where bounty programs fit alongside scanners and penetration tests, and why business-logic flaws still depend on human creativity. Adam explains response metrics, payout structures, public and private programs, and the maturity an organization needs before inviting researchers. Jon describes researcher profiles, reputation, learning paths, and the realities of earning money through vulnerability discovery. The conversation gives organizations a clearer picture of the operational commitment behind a bounty and gives aspiring researchers practical ways to begin building skill and credibility.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Adam Bacchus and Jon Bottarini:
→ Adam Bacchus on LinkedIn
→ Jon Bottarini on LinkedIn
→ HackerOne
Mentioned in this episode:
→ HackerOne
→ Hacker101
→ HackerOne Hacker Report
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Two sides of a bug bounty
02:33 A researcher’s security origin story
06:34 The size and scope of bounty programs
08:00 Safe harbor for security researchers
09:17 Where bug bounties fit in AppSec
11:09 A business-logic vulnerability example
12:57 Root causes and program improvement
14:43 Metrics for running a bounty
19:08 Response-time expectations
20:02 Payouts and program maturity
21:34 Who becomes a bug bounty researcher
23:10 How a new researcher can start
26:14 Reputation and private programs
26:54 The largest bounty payouts
27:54 Life as a security researcher
31:07 Full-time and part-time participation
34:47 Learning resources and final advice
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.