EPISODE · Nov 5, 2018 · 36 MIN
Adam Bacchus and Jon Bottarini -- Two Sides to a Bug Bounty: The Researcher and The Program
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
What does a bug bounty look like from both sides of the relationship? Adam Bacchus and Jon Bottarini of HackerOne compare the responsibilities of the program operator with the experience of the security researcher. They discuss safe-harbor language, where bounty programs fit alongside scanners and penetration tests, and why business-logic flaws still depend on human creativity. Adam explains response metrics, payout structures, public and private programs, and the maturity an organization needs before inviting researchers. Jon describes researcher profiles, reputation, learning paths, and the realities of earning money through vulnerability discovery. The conversation gives organizations a clearer picture of the operational commitment behind a bounty and gives aspiring researchers practical ways to begin building skill and credibility.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Adam Bacchus and Jon Bottarini:→ Adam Bacchus on LinkedIn→ Jon Bottarini on LinkedIn→ HackerOneMentioned in this episode:→ HackerOne→ Hacker101→ HackerOne Hacker ReportFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Two sides of a bug bounty02:33 A researcher’s security origin story06:34 The size and scope of bounty programs08:00 Safe harbor for security researchers09:17 Where bug bounties fit in AppSec11:09 A business-logic vulnerability example12:57 Root causes and program improvement14:43 Metrics for running a bounty19:08 Response-time expectations20:02 Payouts and program maturity21:34 Who becomes a bug bounty researcher23:10 How a new researcher can start26:14 Reputation and private programs26:54 The largest bounty payouts27:54 Life as a security researcher31:07 Full-time and part-time participation34:47 Learning resources and final advice
Embed this episode
What this episode covers
What does a bug bounty look like from both sides of the relationship? Adam Bacchus and Jon Bottarini of HackerOne compare the responsibilities of the program operator with the experience of the security researcher. They discuss safe-harbor language, where bounty programs fit alongside scanners and penetration tests, and why business-logic flaws still depend on human creativity. Adam explains response metrics, payout structures, public and private programs, and the maturity an organization nee...
Ready to play
Adam Bacchus and Jon Bottarini -- Two Sides to a Bug Bounty: The Researcher and The Program
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.