Get a Pentest and security assessment of your IT network.

News

Bug bounty platforms buy researcher silence, violate labor laws, critics say

Bug bounty platforms use NDAs to trade bounty hunter silence for the possibility of a payout. Security researchers report security flaws under NDA and are paid to keep quiet. All organizations need a vulnerability disclosure program (VDP); few need a bug bounty program. HackerOne’s co-founder and CTO Alex Rice defends the practice of providing private bug bounty programs to companies that lack a VDP, citing legal, regulatory, policy and risk management concerns inside customer organizations. A VDP looks like this: Good-faith security researchers tell you your stuff is broken, give you 90 days max to fix it.”]

Source: https://www.csoonline.com/article/3535888/bug-bounty-platforms-buy-researcher-silence-violate-labor-laws-critics-say.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Thousands of Magento websites compromised to serve malware

News

Office 365 Secure Score: An Introduction