Adam Bacchus and Jon Bottarini -- Two Sides to a Bug Bounty: The Researcher and The Program episode artwork

EPISODE · Nov 5, 2018 · 36 MIN

Adam Bacchus and Jon Bottarini -- Two Sides to a Bug Bounty: The Researcher and The Program

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

What does a bug bounty look like from both sides of the relationship? Adam Bacchus and Jon Bottarini of HackerOne compare the responsibilities of the program operator with the experience of the security researcher. They discuss safe-harbor language, where bounty programs fit alongside scanners and penetration tests, and why business-logic flaws still depend on human creativity. Adam explains response metrics, payout structures, public and private programs, and the maturity an organization needs before inviting researchers. Jon describes researcher profiles, reputation, learning paths, and the realities of earning money through vulnerability discovery. The conversation gives organizations a clearer picture of the operational commitment behind a bounty and gives aspiring researchers practical ways to begin building skill and credibility.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Adam Bacchus and Jon Bottarini:→ Adam Bacchus on LinkedIn→ Jon Bottarini on LinkedIn→ HackerOneMentioned in this episode:→ HackerOne→ Hacker101→ HackerOne Hacker ReportFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Two sides of a bug bounty02:33 A researcher’s security origin story06:34 The size and scope of bounty programs08:00 Safe harbor for security researchers09:17 Where bug bounties fit in AppSec11:09 A business-logic vulnerability example12:57 Root causes and program improvement14:43 Metrics for running a bounty19:08 Response-time expectations20:02 Payouts and program maturity21:34 Who becomes a bug bounty researcher23:10 How a new researcher can start26:14 Reputation and private programs26:54 The largest bounty payouts27:54 Life as a security researcher31:07 Full-time and part-time participation34:47 Learning resources and final advice

Episode metadata supplied by the publisher feed · Published Nov 5, 2018

Embed this episode

What does a bug bounty look like from both sides of the relationship? Adam Bacchus and Jon Bottarini of HackerOne compare the responsibilities of the program operator with the experience of the security researcher. They discuss safe-harbor language, where bounty programs fit alongside scanners and penetration tests, and why business-logic flaws still depend on human creativity. Adam explains response metrics, payout structures, public and private programs, and the maturity an organization nee...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Adam Bacchus and Jon Bottarini -- Two Sides to a Bug Bounty: The Researcher and The Program

0:00 36:10

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 36 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on November 5, 2018.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!