Architecture, Network security, Strategy, Vulnerability management

The bug bounty debate: Black Hat 2010 panelists debate the merits of vendors paying for vulnerabilities

August 16, 2010
Alex Stamos of iSEC partners offers his take on the usefulness of incentive programs that encourage researchers to privately report vulnerabilities to vendors, in exchange for cash. While the initiatives might fatten the wallets of bug hunters, some believe it taints the mission of white-hat hackers.
