
DEF CON 32 - The Darkest Side of Bug Bounty - Jason Haddix
Source: YouTube · DEFCONConference · published Oct 16, 2024 · 32:31
Jason exposes the dark side of bug bounty programs, revealing how platforms exploit hunters' work without compensation, companies manipulate vulnerability ratings to avoid payouts, and systemic power imbalances undermine the security ecosystem 0:35.
Key Takeaways:
• Platforms train AI models on hunters' attack data to create threat intelligence feeds and scanners without sharing profits with the original researchers 3:54.
• Cloud security companies monitor top 250 hunters' traffic and patterns to build defenses without compensation 7:15.
• Companies frequently downgrade vulnerability severity ratings or group similar bugs to minimize payouts when budgets are exhausted 11:03.
• Celebrity hunters receive preferential treatment while newcomers face significant disadvantages in the bug bounty ecosystem 25:05.
The future of bug bounty depends on platforms recognizing that hackers are their most valuable product and implementing fairer, more transparent systems 31:55.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
[Applause] thank you thank you so much um my name is Jason um I'm going to try to keep my energy up for this talk uh I usually do when I speak uh but I have a little bit of a situation going on right home right now at home my wife's in the ER um my kids are watching my other kids and I've done four talks this week already so I'm going to try to keep it up but if I'm a little bit less than super super Jason hadex I'm sorry um but I'm going to do my best so this talk I've wanted to do for a long time it's called The Dark Side of bug Bounty and it is a collection of notes around the kind of worst possible scenarios that can happen in bug Bounty programs so we did a little survey originally like what you guys do but there are four primary types of people or three primary types of people in the…