DEF CON 32 - The Darkest Side of Bug Bounty - Jason Haddix

DEF CON 32 - The Darkest Side of Bug Bounty - Jason Haddix

Source: YouTube · DEFCONConference · published Oct 16, 2024 · 32:31

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Jason exposes the dark side of bug bounty programs, revealing how platforms exploit hunters' work without compensation, companies manipulate vulnerability ratings to avoid payouts, and systemic power imbalances undermine the security ecosystem 0:35.

Key Takeaways:
• Platforms train AI models on hunters' attack data to create threat intelligence feeds and scanners without sharing profits with the original researchers 3:54.
• Cloud security companies monitor top 250 hunters' traffic and patterns to build defenses without compensation 7:15.
• Companies frequently downgrade vulnerability severity ratings or group similar bugs to minimize payouts when budgets are exhausted 11:03.
• Celebrity hunters receive preferential treatment while newcomers face significant disadvantages in the bug bounty ecosystem 25:05.

The future of bug bounty depends on platforms recognizing that hackers are their most valuable product and implementing fairer, more transparent systems 31:55.

Sources:

  • 0:35 Introduction to "The Dark Side of Bug Bounty" talk
  • 3:54 AI exploitation of bug hunter research
  • 7:15 Cloud WAF companies monitoring hunters
  • 11:03 Companies manipulating vulnerability ratings
  • 25:05 Power disparity between celebrity and new hunters
  • 31:55 Closing thoughts on improving bug bounty

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

[Applause] thank you thank you so much um my name is Jason um I'm going to try to keep my energy up for this talk uh I usually do when I speak uh but I have a little bit of a situation going on right home right now at home my wife's in the ER um my kids are watching my other kids and I've done four talks this week already so I'm going to try to keep it up but if I'm a little bit less than super super Jason hadex I'm sorry um but I'm going to do my best so this talk I've wanted to do for a long time it's called The Dark Side of bug Bounty and it is a collection of notes around the kind of worst possible scenarios that can happen in bug Bounty programs so we did a little survey originally like what you guys do but there are four primary types of people or three primary types of people in the…