For the Bug Bounties section:
A greater reward for a finding being fixed can be dangerous unless there's a specific goal in mind. If the goal is for the finding to be fixed ASAP, then researchers will be incentivized by either, helping to fix the issue, or simply pestering Devs to fix it. Worse, threatening to exploit or disclose in an unagreed upon manner sooner. Breakers are more often than you think, not builders, or visaversa. Hell, I can find SQLi like the best of em, but I am not intricately familiar with parameterization as a remediation method. If this seems nitpicky, it's because I've seen stuff happen man. I've seen things...
I can see your gaze into the distance at the end there.
Definitely great info. How the bug bounties are built is important. This budget would just reserve some funds for the system built. I think we have some folks with experience in bug bounty programs willing to build everything out if we get funds for it.
Downvoting a post can decrease pending rewards and make it less visible. Common reasons:
Submit