EPISODE · May 29, 2018 · 29 MIN
Devin McMasters -- Bug Bounty with a Side of Empathy
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
A bug bounty can create a productive relationship with security researchers—or damage trust on both sides. Devin McMasters joins Chris to explain how organizations can design programs that produce useful findings while treating researchers fairly. He compares crowdsourced security with traditional penetration testing, discusses public and private programs, and describes the operational maturity required before inviting outside reports. The conversation covers vulnerability types, payout budgets, incident-response workflows, reputation, and common program mistakes. Devin repeatedly returns to empathy: companies may set the final rules, but researchers invest real time and may depend on rewards, so clear communication and respectful decisions are essential to a sustainable bug bounty program.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Devin McMasters:→ Devin McMasters on LinkedInMentioned in this episode:→ Bugcrowd→ HackerOneFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Bug bounties with empathy01:41 Devin McMasters’s developer background05:16 What a bug bounty program does06:01 Why organizations run bug bounties07:50 Building a relationship with researchers09:57 Bug bounty versus penetration testing12:21 The findings a bounty can uncover14:37 Payouts and program budgets17:20 Public and private bug bounties18:08 Operational maturity before launch19:59 Reputation in the researcher community22:03 Incident response and remediation workflows24:06 Common bug bounty mistakes25:03 Applying empathy to program decisions28:00 Final takeaways
Embed this episode
What this episode covers
A bug bounty can create a productive relationship with security researchers—or damage trust on both sides. Devin McMasters joins Chris to explain how organizations can design programs that produce useful findings while treating researchers fairly. He compares crowdsourced security with traditional penetration testing, discusses public and private programs, and describes the operational maturity required before inviting outside reports. The conversation covers vulnerability types, payout budge...
Ready to play
Devin McMasters -- Bug Bounty with a Side of Empathy
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.