S3 Ep19.5: How NOT to be a bug bounty hunter

Published: Feb. 12, 2021, 2 p.m.

In this special mini-episode, Paul Ducklin talks to Sophos cybersecurity expert Chester Wisniewski about bug bounty hunting.

\n


\n

How does bug bounty hunting work? What should you do if you get a bug report that doesn't follow established protocol? Chester tells you how to deal with so-called "beg bounties", where self-styled "experts" beg you for money or even threaten you with ill-defined "problems" they claim to have found.

\n


\n

https://news.sophos.com/en-us/have-a-domain-name-beg-bounty-hunters-may-be-on-their-way

\n


\n

https://nakedsecurity.sophos.com/beware-of-technical-experts-bombarding-you-with-bug-reports

\n


\n

Original music by Edith Mudge

\n


\n

Got questions/suggestions/stories to share?

\n

Email tips@sophos.com

\n

Twitter @NakedSecurity

\n

Instagram @NakedSecurity