Week 12 – Journal Entry 13
After reading Kiran Sridhar’s article about an economic model for bug bounties it asks the question if bug bounties improve the cybersecurity of all organizations and do HackerOne hackers help firms find the vulnerabilities that their internal technical teams missed? Looking over the findings, it seems that bug bounties are not as significant in increasing hacker participation for organizations as they want to be able to gain experience and build their reputations in other ways. To me this makes sense because if you’re starting to learn hacking and want to get better, one would feel more comfortable being able to gain knowledge through shadowing and slowly making their skills prominent as they move forward. It’s better to take that route as opposed to being thrown into the fire of trying to crack a bug bounty in hopes you can make money that probably won’t reward you as much compared to what the actual cybersecurity team of an organization gets paid daily, monthly, yearly, etc.
Leave a Reply