Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Devin McMasters -- Bug Bounty with a Side of Empathy

30 min29 maj 2018

Om avsnittet

A bug bounty can create a productive relationship with security researchers—or damage trust on both sides. Devin McMasters joins Chris to explain how organizations can design programs that produce useful findings while treating researchers fairly. He compares crowdsourced security with traditional penetration testing, discusses public and private programs, and describes the operational maturity required before inviting outside reports. The conversation covers vulnerability types, payout budgets, incident-response workflows, reputation, and common program mistakes. Devin repeatedly returns to empathy: companies may set the final rules, but researchers invest real time and may depend on rewards, so clear communication and respectful decisions are essential to a sustainable bug bounty program.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Devin McMasters:
Devin McMasters on LinkedIn

Mentioned in this episode:
Bugcrowd
HackerOne

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Bug bounties with empathy
01:41 Devin McMasters’s developer background
05:16 What a bug bounty program does
06:01 Why organizations run bug bounties
07:50 Building a relationship with researchers
09:57 Bug bounty versus penetration testing
12:21 The findings a bounty can uncover
14:37 Payouts and program budgets
17:20 Public and private bug bounties
18:08 Operational maturity before launch
19:59 Reputation in the researcher community
22:03 Incident response and remediation workflows
24:06 Common bug bounty mistakes
25:03 Applying empathy to program decisions
28:00 Final takeaways

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.