Ah yes, another high profile bug bounty forcing non-disclosure — even for fixed bugs.
🤦🏻♀️
It’s the bugs they won’t fix that will put users at risk.
All orgs need a vulnerability disclosure program that doesn’t ban Disclosure.
But what do I know.
I just coauthored the standard
#GPT
“But it’s a bug bounty & they are paying so it’s fair to ask for non disclosure”
That’s fine if everything submitted is paid work, like a penetration test.
Oh, only paying selectively & only the first of any duplicates?
That’s labor abuse & the worst gig economy deal out there.
“But pen tests don’t get you all the eyeballs”
Neither do bug bounties - you get a random number of eyeballs willing to sign NDAs.
If orgs actually care about security, they cast as wide a net s as possible to get the best researchers - especially those who won’t sign NDAs.
“This is better than no bug bounty”
No, it isn’t.
It breeds a false sense of security for users & the org itself, while actively excluding the highest skilled researchers who will never sign an NDA for speculative pay or who want to see the bugs FIXED as their motivation.