DEF CON 33 - Managing Bug Bounties @ Scale - Gabriel Nitu, Jay Dancer, PayPal, Ryan Nolette & Goshak

DEF CON 33 - Managing Bug Bounties @ Scale - Gabriel Nitu, Jay Dancer, PayPal, Ryan Nolette & Goshak

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 58:45

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Optimized Summary (Revised & Enhanced Based on Feedback):

[BLUF] Bug bounty programs are evolving from transactional, volume-driven initiatives to collaborative, impact-focused ecosystems. The shift is driven by rising AI-generated reports—often verbose, unactionable, and misleading—researcher demand for industry-specific expertise (e.g., PCI DSS compliance), and a growing emphasis on transparent, personal engagement. Success now depends on clear context, meaningful impact, and deep researcher-vendor collaboration, with a strong focus on quality over quantity.

Key Takeaways:

  1. AI-Generated Reports Are a Major Challenge
    AI tools (e.g., Exploit, AI-powered attack vectors) are now generating real, valid vulnerabilities—not just fabricated content. While these reports can be technically accurate, they often lack clear impact, proof of concept, or real-world validation, leading to significant triage overhead. Reports are frequently overly verbose, scripted, or filled with "sloppy" content (e.g., 400+ word essays), making them difficult to evaluate.
    Action: Programs must require clear impact statements, proof of concept, and concise summaries to ensure reports are actionable and reduce noise.

  2. Researchers Are Shifting Toward Industry-Specific Expertise
    Top researchers are now deeply specialized—e.g., in fintech, healthcare, or compliance. Companies are increasingly seeking industry-qualified hackers who understand domain-specific regulations (like PCI DSS) and operational nuances. This trend enables more relevant, high-impact findings and reduces the risk of false positives.
    Action: Programs should target and reward specialized researchers, build industry-specific engagement paths, and offer compliance-aware guidance.

  3. Collaboration Is Central—Not Just Submission
    The ideal relationship is no longer transactional. Researchers are now seen as **s

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Alrighty. Hi everyone. This is Voices from the Front Lines. Uh I'm Joe Monet Carlo. I'm your moderator for this lovely panel of folks. So uh we're going to get this kicked off. Uh so we're going to kick it off with introductions. Please tell us who you are, what your company uh is, and what your role is in your organization. >> Well, hello everyone. I'm >> uh my name is Tyson. Uh I am from PayPal. I run the bug bunch program for uh PayPal. Yeah. >> Hey everyone, Gabriel Splunk running the bug for Splunk dert and obvious security. Uh I'm the technical lead for the exposure program. Hello everyone. I'm >> Hi, I'm Jay. I'm with Shopify. So we're on the same page that is the green app but not the music green app. Just a word. Uh I've been on Shopify for about 8 years and I spent the last five …