Drawing upon crowdsourcing, bug bounty programs (BBPs) are entering the mainstream security practice in organizations. We analyze and recommend best practices in five main BBP areas: scoping of BBPs, timing of crowd engagement, submission quality, firm-researcher communication, and hacker motivation.
No takes yet. Share an insight, caveat, or question.
Malladi et al. (2019) studied this question.
Synapse has enriched 3 closely related papers on similar clinical questions. Consider them for comparative context: