Get a Pentest and security assessment of your IT network.

News

Bug bounty platforms buy researcher silence, violate labor laws, critics say

Bug bounty platforms use NDAs to trade bounty hunter silence for the possibility of a payout. Security researchers report security flaws under NDA and are paid to keep quiet. All organizations need a vulnerability disclosure program (VDP); few need a bug bounty program. HackerOne’s co-founder and CTO Alex Rice defends the practice of providing private bug bounty programs to companies that lack a VDP, citing legal, regulatory, policy and risk management concerns inside customer organizations. A VDP looks like this: Good-faith security researchers tell you your stuff is broken, give you 90 days max to fix it.”]

Source: https://www.csoonline.com/article/3535888/bug-bounty-platforms-buy-researcher-silence-violate-labor-laws-critics-say.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Botnet authors use Evernote account as C&C Server

News

Canadian agency breached as hackers exploit CVE-2017-5638 flaw in Apache Struts 2