Devin McMasters -- Bug Bounty with a Side of Empathy episode artwork

EPISODE · May 29, 2018 · 29 MIN

Devin McMasters -- Bug Bounty with a Side of Empathy

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

A bug bounty can create a productive relationship with security researchers—or damage trust on both sides. Devin McMasters joins Chris to explain how organizations can design programs that produce useful findings while treating researchers fairly. He compares crowdsourced security with traditional penetration testing, discusses public and private programs, and describes the operational maturity required before inviting outside reports. The conversation covers vulnerability types, payout budgets, incident-response workflows, reputation, and common program mistakes. Devin repeatedly returns to empathy: companies may set the final rules, but researchers invest real time and may depend on rewards, so clear communication and respectful decisions are essential to a sustainable bug bounty program.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Devin McMasters:→ Devin McMasters on LinkedInMentioned in this episode:→ Bugcrowd→ HackerOneFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Bug bounties with empathy01:41 Devin McMasters’s developer background05:16 What a bug bounty program does06:01 Why organizations run bug bounties07:50 Building a relationship with researchers09:57 Bug bounty versus penetration testing12:21 The findings a bounty can uncover14:37 Payouts and program budgets17:20 Public and private bug bounties18:08 Operational maturity before launch19:59 Reputation in the researcher community22:03 Incident response and remediation workflows24:06 Common bug bounty mistakes25:03 Applying empathy to program decisions28:00 Final takeaways

Episode metadata supplied by the publisher feed · Published May 29, 2018

Embed this episode

A bug bounty can create a productive relationship with security researchers—or damage trust on both sides. Devin McMasters joins Chris to explain how organizations can design programs that produce useful findings while treating researchers fairly. He compares crowdsourced security with traditional penetration testing, discusses public and private programs, and describes the operational maturity required before inviting outside reports. The conversation covers vulnerability types, payout budge...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Devin McMasters -- Bug Bounty with a Side of Empathy

0:00 29:30

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 29 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on May 29, 2018.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!