Crowdsourced flaw-finding cheaper than in-house bug hunters ? The Register
A study into the once-controversial practice of vulnerability rewards programs (VPRs) – paying researchers bug bounties for reporting security flaws – has found that for browser builders, the practice is not only more effective at spotting problems that hiring code-checkers, it's also much better value for the money.
---------------
So Mitch have you seen this done(close up)? What are the issues?
A study into the once-controversial practice of vulnerability rewards programs (VPRs) – paying researchers bug bounties for reporting security flaws – has found that for browser builders, the practice is not only more effective at spotting problems that hiring code-checkers, it's also much better value for the money.
---------------
So Mitch have you seen this done(close up)? What are the issues?
Comment