Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Adam Bacchus and Jon Bottarini -- Two Sides to a Bug Bounty: The Researcher and The Program

36 min5 november 2018

Om avsnittet

What does a bug bounty look like from both sides of the relationship? Adam Bacchus and Jon Bottarini of HackerOne compare the responsibilities of the program operator with the experience of the security researcher. They discuss safe-harbor language, where bounty programs fit alongside scanners and penetration tests, and why business-logic flaws still depend on human creativity. Adam explains response metrics, payout structures, public and private programs, and the maturity an organization needs before inviting researchers. Jon describes researcher profiles, reputation, learning paths, and the realities of earning money through vulnerability discovery. The conversation gives organizations a clearer picture of the operational commitment behind a bounty and gives aspiring researchers practical ways to begin building skill and credibility.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Adam Bacchus and Jon Bottarini:
Adam Bacchus on LinkedIn
Jon Bottarini on LinkedIn
HackerOne

Mentioned in this episode:
HackerOne
Hacker101
HackerOne Hacker Report

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Two sides of a bug bounty
02:33 A researcher’s security origin story
06:34 The size and scope of bounty programs
08:00 Safe harbor for security researchers
09:17 Where bug bounties fit in AppSec
11:09 A business-logic vulnerability example
12:57 Root causes and program improvement
14:43 Metrics for running a bounty
19:08 Response-time expectations
20:02 Payouts and program maturity
21:34 Who becomes a bug bounty researcher
23:10 How a new researcher can start
26:14 Reputation and private programs
26:54 The largest bounty payouts
27:54 Life as a security researcher
31:07 Full-time and part-time participation
34:47 Learning resources and final advice

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.