Главная
Study mode:
on
1
Intro
2
A bit about me
3
The Nature of Disclosure
4
Rain Forest Policy (RFPolicy)
5
The Trustworthy Computing Memo
6
Disclosure Drives Action
7
Remember Netscape?
8
Vendor Agnostic Bounty Programs
9
How vendor agnostic bounties work
10
Bug Bounty as a Service (BBaaS)
11
Evolving Marketplace
12
Exploit Intelligence Marketplace
13
Economy in Action
14
Lessons from Hacking Team Leak
15
How to Get Oday: Vulnerability Brokers
16
Bounty Programs Killing Exploits
17
Beyond Just Security Patches
18
Living in the Shadow Brokers Reality
19
Killing NSA's Tailored Access Operation exploits
20
Shades of Stuxnet
21
Killing CIA's Closed Network Infiltration Tool
22
Pwn2own Inspired Improvements
23
Benefits to Researchers
24
Conclusion
Description:
Explore an oral history of bug bounty programs in this BSides Nashville 2018 conference talk. Delve into the evolution of vulnerability disclosure, from the Rain Forest Policy to the Trustworthy Computing Memo. Examine the impact of disclosure on driving action and the emergence of vendor-agnostic bounty programs. Learn about Bug Bounty as a Service (BBaaS) and the developing exploit intelligence marketplace. Analyze lessons from the Hacking Team leak and the role of vulnerability brokers. Investigate how bounty programs are affecting exploit development and their influence beyond security patches. Consider the implications of living in the Shadow Brokers reality and the impact on NSA and CIA tools. Discover how Pwn2Own has inspired improvements and the benefits for security researchers in this comprehensive overview of the bug bounty ecosystem.

An Oral History of Bug Bounty Programs

Add to list