Overview
Syllabus
Intro
Agenda
Mission
Mantra
Security team
Environment
Data Centers
Risk vs Threat
When to catch bugs
Big hammer approach
Pen testing
Bug bounties
What gets tested
Objections from product and engineering
Bugcrowd
Points only bug bounty
Metrics driven
Starting to pay
Reports of tickets
Hows it going
Average payout
Response time
Reward breakdown
Payout breakdown
Average payouts
Severity of bugs
Marketing push
Working with the crowd
Reducing workload
External security team
Independent testers
Making mistakes
Would we do it again
Getting engineers involved
Lockpicking Happy Hour
Firewall Free Fridays
Classes
Internal blog
Security bugs
Education
Security challenges
XML
Password Shadow
XSS
QA
Points
Taught by
LASCON