Get a Pentest and security assessment of your IT network.

News

Bug bounty platforms buy researcher silence, violate labor laws, critics say

Bug bounty platforms use NDAs to trade bounty hunter silence for the possibility of a payout. Security researchers report security flaws under NDA and are paid to keep quiet. All organizations need a vulnerability disclosure program (VDP); few need a bug bounty program. HackerOne’s co-founder and CTO Alex Rice defends the practice of providing private bug bounty programs to companies that lack a VDP, citing legal, regulatory, policy and risk management concerns inside customer organizations. A VDP looks like this: Good-faith security researchers tell you your stuff is broken, give you 90 days max to fix it.”]

Source: https://www.csoonline.com/article/3535888/bug-bounty-platforms-buy-researcher-silence-violate-labor-laws-critics-say.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

SEA has stolen invoices that shows Microsoft charges FBI for user data

News

Greek police arrested a man running the BTC-e Bitcoin exchange to launder more than US$4bn worth of the Bitcoin