S3 Ep19.5: How NOT to be a bug bounty hunter

Published: Feb. 12, 2021, 1:42 p.m.

In this special mini-episode, Paul Ducklin talks to Sophos cybersecurity expert Chester Wisniewski about bug bounty hunting.\n\nHow does bug bounty hunting work? What should you do if you get a bug report that doesn't follow established protocol? Chester tells you how to deal with so-called "beg bounties", where self-styled "experts" beg you for money or even threaten you with ill-defined "problems" they claim to have found.\n\nhttps://news.sophos.com/have-a-domain-name-beg-bounty-hunters-may-be-on-their-way\nhttps://nakedsecurity.sophos.com/beware-of-technical-experts-bombarding-you-with-bug-reports\n\nOriginal music by Edith Mudge (https://www.edithmudge.com)\n\nGot questions/suggestions/stories to share?\nEmail: tips@sophos.com\nTwitter: NakedSecurity (https://twitter.com/nakedsecurity)\nInstagram: NakedSecurity (https://instagram.com/nakedsecurity)