Resilient Cyber

S2E22: HackerOne - Bug Bounty, Vulnerability Disclosure and Ethics


Listen Later

Nikki: I've spent a number of years studying vulnerability chaining and using low and medium vulnerabilities in combination to create very critical attacks. Do you see this as a common method for attacks in the wild?

Chris: we're continuing to see the growth of bug bounty programs, such as HackerOne. How do you think these programs contrast (or compliment) companies internal pen test/red teams for example? 

Nikki: Vulnerability management is an incredibly complex topic for a lot of organizations. Do you think bug bounty programs and Vulnerability Disclosure Programs (VDP) are helping to mature those programs?

Chris: How do companies have a level of assurance that the hackers will conduct the activities ethically? 

Nikki: I think there's still sometimes a disconnect between what hackers and pentesters know about vulnerabilities and the actual attack paths, and the remediation teams that are working to prevent these types of attacks. Do you think there's a need to educate more Blue teamers on specific types of attacks and how they are conducted?

Chris: on the flip side, for hackers interested in bug bounty, how can they best go about getting started?

Nikki: we're starting to see more development teams taking responsibility for security — we frequently hear the term "shifting left." Is that a trend you are observing as well?

Chris: thoughts on log4shell?

...more
View all episodesView all episodes
Download on the App Store

Resilient CyberBy Chris Hughes

  • 4.9
  • 4.9
  • 4.9
  • 4.9
  • 4.9

4.9

15 ratings


More shows like Resilient Cyber

View all
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

627 Listeners

The Cloudcast by Massive Studios

The Cloudcast

152 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,003 Listeners

AWS Podcast by Amazon Web Services

AWS Podcast

203 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

7,875 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

167 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

187 Listeners

Cloud Security Podcast by Cloud Security Podcast Team

Cloud Security Podcast

57 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

129 Listeners

CISO Tradecraft® by CISO Tradecraft®

CISO Tradecraft®

48 Listeners

The Ezra Klein Show by New York Times Opinion

The Ezra Klein Show

15,306 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

33 Listeners

No Priors: Artificial Intelligence | Technology | Startups by Conviction

No Priors: Artificial Intelligence | Technology | Startups

122 Listeners

AI Security Podcast by Kaizenteq Team

AI Security Podcast

4 Listeners

Threat Vector by Palo Alto Networks by Palo Alto Networks and N2K Networks

Threat Vector by Palo Alto Networks

34 Listeners