Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Do you use the same (de)value justification when billing clients for your security services? Or, maybe, it's precisely because you're all security professionals who make a living by identifying security flaws and you'd prefer not to introduce competition from the open market. Unattractive bug bounties ensure you can justify your services.

Just like Uber is to the taxi industry, bug bounties are a disruption to your own business model.



I can understand why you'd believe this, but I am actually a fan of bug bounty programs. I have both participated in and managed bug bounty programs before and I think they are absolutely a win for our industry. Frankly, they occupy a different market positioning than my own work.

Of course, you're free to believe or disbelieve that, but each of my points stand on their own weight regardless of my own occupation.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: