Chapter 54. Demystifying Bug Bounty Programs
Aldo Salas
I’ve been involved in a couple of companies where the use of a bug bounty program was generally perceived as negative. There are a number of reasons I’ve heard many reasons why implementing a bug bounty program was not sought after at that time, including:
-
The program can be expensive.
-
It takes several months before seeing results.
-
It’s hard to manage.
-
Researchers can be hostile.
The financial issue is a misplaced concern, since it’s significantly cheaper to find a critical vulnerability by doing a routine pen test, or through a controlled bug bounty program than having one of your customers discover that vulnerability and demand a fix as soon as possible.
The consequences of customers and prospects finding security issues in an application can range from a customer reducing their confidence in your product, to actually losing an opportunity because the prospect did not consider the application to be secure enough. This is vastly more expensive than an average bug bounty program.
The results of a bug bounty program can be obtained almost instantly because the researchers involved are usually highly motivated and work across multiple time zones, allowing for continuous progress. Lastly, the challenges of managing the program and coordinating with researchers can be easily addressed by using a bug bounty partner or platform, which streamlines the process and facilitates effective collaboration.
Preparing the Test ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access