Critics say bug bounty programs buy researcher silence, may violate labor law, and are less effective when they are closed and have NDAs placed on them
When Jonathan Leitschuh found a catastrophic security vulnerability in Zoom, the popular videoconferencing platform …
Bug bounty platforms buy researcher silence, violate labor laws, critics say Me: “My legal analysis suggests those workers...should at least be getting minimum wage, overtime compensation, and unemployment insurance,” https://www.csoonline.com/... via @csoonline
Great summary of exactly the issue with bug bounties. “Many eyes” is a myth. You need the right set of eyes, and there are just very few of them. https://twitter.com/... https://twitter.com/...
“Bug bounties are best when transparent and open. The more you try to close them down and place NDAs on them, the less effective they are, the more they become about marketing rather than security.” https://www.csoonline.com/...?
So the companies whose worst impulses the bug-management platforms were supposed to be blunting ended up running the show, and the reporting platforms became a catch-and-kill system for vulns. https://www.csoonline.com/... 16/
New: My two-month investigation of the bug bounty platforms reveals serious concerns about their business practices, and accusations that NDAs are being used to cover up security issues. 1/ https://www.csoonline.com/... @CSOonline