Showing posts with label security researcher. Show all posts
Showing posts with label security researcher. Show all posts

Monday, April 17, 2023

Always check for a bounty program beforehand

from here and here

I'm not saying there's anything wrong with wanting something in return for your efforts, but be honest about your motivations and be more curious about how that process works. Don't just assume everyone hands out bug bounties, because they don't, and if the company in question doesn't then it's best to not even mention it.

Frankly, when you approach a company with a report that mentions a deadline to act and payment they never agreed to, quite a few are going to interpret it as some sort of shakedown or blackmail. One of the best indicators that a company won't do that is if they do in fact have a documented bug bounty program.

Thursday, August 26, 2021

What could possibly go wrong?

from here and here (image source)

Do we really need to know how to scale up spear phishing through AI-enabled automation right now? 

Don't defenders have enough unsolved problems to worry about without adding more?

When offensive security research is valued more highly than defensive security research, does that really help us to better protect ourselves?

Thursday, January 28, 2021

We have seen the vulnerability and it is us

from here and here

When even security researchers are successfully targeted, that's all the proof one should need that no one is immune to social engineering

Wednesday, September 9, 2020

So much for "trust but verify"

from here

Trusting without verifying is basically blind faith, and that's no way to hold an election. Voting technology vendors should not get to decide when, where, how, or by whom their technology is tested, and they certainly shouldn't be soliciting their customers to call the feds on students doing that testing.

Wednesday, February 6, 2019

The best defense isn't always a good offense

from here

I can't imagine a C-level executive who assaults researchers will remain at the C-level for very long, at least not unless he's representative of the culture at Atrient.