Live data from Hacker News

Meet the bughunters: the hackers in India protecting your data

theguardian.com

1–10 of 17 posts

Re: Meet the bughunters: the hackers in India protecting your data

#3
post #2

Amazing that all publicly traded companies are not by law required to have bug bounties. Same goes for any major open source project too.

At what point should a piece of software have a bug bounty? It seems forcing bug bounties would cause them to become purposefully convoluted to obtain

Re: Meet the bughunters: the hackers in India protecting your data

#4
post #3
post #2

Amazing that all publicly traded companies are not by law required to have bug bounties. Same goes for any major open source project too.

At what point should a piece of software have a bug bounty? It seems forcing bug bounties would cause them to become purposefully convoluted to obtain

Just even having a page, with a small bounty, and a secure means of submitting a exploitable bug. If you want to dig deeper, I'd contact professional bug hunters and ask them how to insure that the value on the bug matches the reward.

Re: Meet the bughunters: the hackers in India protecting your data

#5
post #2

Amazing that all publicly traded companies are not by law required to have bug bounties. Same goes for any major open source project too.

Open source projects rarely have a budget for development, let alone bug bounties.

Re: Meet the bughunters: the hackers in India protecting your data

#9
post #8

> rupee millionaire I don't wish to put down Mr Prakash's achievements, but is that actually a celebrated figure in India - or at ~£10.6k is the word 'millionaire' just a sensationalism for our benefit?

approx 1 year salary for a guy working in IT sector with 2-3 years experience

Re: Meet the bughunters: the hackers in India protecting your data

#10
post #4
post #3

Earlier quoted context omitted.

At what point should a piece of software have a bug bounty? It seems forcing bug bounties would cause them to become purposefully convoluted to obtain

Just even having a page, with a small bounty, and a secure means of submitting a exploitable bug. If you want to dig deeper, I'd contact professional bug hunters and ask them how to insure that the value on the bug matches the reward.

And if you can't afford to pay a bounty just don't write software right?

Don't you think it's odd your answer to what you are replying to is "I have no idea, ask someone who knows" yet you feel compelled to weigh in on who should not be allowed to write/distribute software?

Post reply on HN