I like the picture at the beginning of some CLI novice trying to git push his home directory
That reminds me of my idea to create "tech" stock imagery that isn't a joke
Teen Becomes First Hacker to Earn $1M Through Bug Bounties
11–20 of 178 posts
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#12Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#13From a purely fiscal point of view, why hire expensive full time staff to go digging when you can just throw a few sheckles at stuff as it comes up?
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#14Just leaving this here: https://coincircle.com/l/50VVxbObg3
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#15I like the picture at the beginning of some CLI novice trying to git push his home directory
I like the random nucleotide sequence in the background. super relevant.
I want to believe.
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#16I'm very happy for the kid and like the idea that these programs are available but does this incentivise companies to effectively outsource their bug finding? From a purely fiscal point of view, why hire expensive full time staff to go digging when you can just throw a few sheckles at stuff as it comes up?
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#17I'm very happy for the kid and like the idea that these programs are available but does this incentivise companies to effectively outsource their bug finding? From a purely fiscal point of view, why hire expensive full time staff to go digging when you can just throw a few sheckles at stuff as it comes up?
Outsourcing bug finding is only a retroactive solution, not a proactive one
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#18I wish I had a knack for this type of work. That's quite a bit of cash. I do feel I am a competent software engineer, but understanding data structures and algorithms doesn't necessarily correlate to one's ability to identify security vulnerabilities.
No, but it does suggest that you're likely capable of learning security work. Just like your data structure and algorithm knowledge didn't come for free, nobody is born knowing how to find security problems. You need to work for it.
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#19I'm very happy for the kid and like the idea that these programs are available but does this incentivise companies to effectively outsource their bug finding? From a purely fiscal point of view, why hire expensive full time staff to go digging when you can just throw a few sheckles at stuff as it comes up?
Also, a bug bounty usually limits the scope a lot more than a typical pentest does, i.e. no testing of infrastructure security, internal networks etc..
Lastly, if your bug bounty is high enough to make highly skilled people spent time to find your bugs its probably cheaper to just higher some security folks yourself and prevent excessive payouts (by preventing bugs).
Of course all of this does not stop some C-levels from using a bug bounty as replacement, but the issue is not as clear cut and especially the last point should even make sense to non-technical people.
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#20I'm very happy for the kid and like the idea that these programs are available but does this incentivise companies to effectively outsource their bug finding? From a purely fiscal point of view, why hire expensive full time staff to go digging when you can just throw a few sheckles at stuff as it comes up?