May 2021 Summaries
6 posts from Bugcrowd
Filter
Month:
Year:
Post Summaries
Back to Blog
Vulnerability Disclosure Programs (VDPs) are structured ways for companies to accept reports of security vulnerabilities from researchers. Kudos points were mistakenly used as a way to get invited to private programs, leading to duplicate abuses and confusion among researchers. To clarify the purpose of VDPs, Bugcrowd will be eliminating points from them starting June 1st, aiming to provide a safe and low-noise approach for researchers who want to report vulnerabilities to companies. Researchers should participate in VDPs if they want to protect users by identifying security vulnerabilities, or if they believe a public disclosure is possible. Making high-priority submissions on Bugcrowd will increase chances of receiving private program invitations.
May 27, 2021
661 words in the original blog post.
Many organizations recognize the value and benefits of a Vulnerability Disclosure Program (VDP), but not having one can lead to severe consequences such as missed opportunities for security improvements, damage to customer trust, and increased financial losses due to undetected vulnerabilities. Without a VDP, an organization's lack of transparency in reporting vulnerabilities can harm its reputation and make it more difficult to build trust with customers and stakeholders. On the other hand, implementing a well-structured VDP can help organizations improve their security posture, enhance customer relationships, and demonstrate a commitment to responsible disclosure practices.
May 26, 2021
113 words in the original blog post.
A crowdsourced security program can be an effective way to identify vulnerabilities in an organization's assets, but it requires careful consideration and trust in the crowd. The assumption that the "crowd" is a malicious entity is often based on misunderstandings about black hat hackers who may not need permission to find vulnerabilities in publicly facing systems. By engaging the crowd, organizations can emulate what black/grey hats would do in the wild, but with a twist - they can learn about and remediate issues before nefarious parties do. The benefits of this approach include gaining an accurate picture of exposure, increasing the security posture, and reducing the attractiveness to attackers. However, concerns about trusting the crowd arise from worries that researchers may sell or exploit found vulnerabilities on the black/grey market. To address these concerns, Bugcrowd's platform uses a pyramid structure with multiple tiers of researchers, including those with verified identities and trust scores, to ensure responsible behavior. The platform also encourages organizations to avoid artificial barriers to talent and instead focus on leveraging the collective expertise of the crowd to augment their security team.
May 25, 2021
2,452 words in the original blog post.
Vulnerabilities are components of code that can be exploited to negatively impact security, and according to ISO/IEC 29147:2018, they refer to behaviors or conditions in systems that violate implicit or explicit security policies. The cause of vulnerabilities is often due to human error, inadequate design, or poor coding practices, making them a common occurrence in software development. Vulnerabilities can be surfaced through automated tools, manual testing, and bug bounty programs, while experts who specialize in vulnerability assessment and penetration testing are responsible for identifying them. While the idea of intentionally becoming vulnerable may seem humorous, it is essential to prioritize security and take steps to prevent vulnerabilities from being exploited.
May 20, 2021
116 words in the original blog post.
Unaccepted invites at Bugcrowd are set to expire after 8 calendar days, starting May 17th at 17:00 Pacific Time (UTC-7), in an effort to allow more researchers to participate in private programs by sending them to other interested parties. This change aims to prevent invitations from being hoarded and promote a fair distribution of opportunities among the community. Existing invites will not expire immediately, but will have the new timeout applied during the next week, allowing users to review and accept or decline them as needed.
May 13, 2021
528 words in the original blog post.
A larger scope is beneficial for engagement as it increases the time required to find an issue, making it easier for researchers to discover new vulnerabilities, thereby increasing the probability of participation. Increasing the program's scope allows the organization to simulate how attackers would approach their entire attack surface, providing a more accurate and real-world reflection of how attackers engage. This is especially important in open-scope programs, where no asset belonging to the organization is out of scope. Running an open-scope program with a large scope enables the organization to emulate the attacker's approach, making it easier for researchers to find issues and increasing engagement. The value of trust, recognition, and swag cannot be understated in increasing engagement, as they build relationships and provide exclusive experiences that incentivize participation. Engaged program owners created engaged programs; disengaged program owners create disengaged programs, highlighting the importance of treating researchers with respect and building meaningful relationships to increase engagement. Addressing barriers to entry is crucial for a successful program, and running the wrong program type or imposing limitations can lead to low engagement.
May 04, 2021
4,751 words in the original blog post.