Overview
Syllabus
Intro
About me
About the panelists
Scope of the bounty programs
Numbers and results
What is a bug bounty
What do you wish youd known before launching
How to forecast and plan both resourcing and budget
Understanding the value of a vulnerability
Communication is key
Mature OPSEC practice
Competition
Complementing Security
Silent Circle
Training
Private vs Public
Vendor Agreements
Bug Bounty Program
Disclosure
Balancing the Bounty
Tactical Resources
Team Structure
Handling lowquality bugs
Lowquality bugs
Respect your research
Technical risk vs business risk
How to get application teams engaged
Prioritize internally
Technical vs business risk
Reward
Out of Scope
Rewards
Scope
Charles
Patrick F
Taught by
Black Hat