Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The road to hell is paved in good intentions. If I had to guess, a well meaning and experienced engineer or engineering leader proposed launching a legit bug bounty program. Maybe they pitched the idea to their boss, showing them hackerone or bugcrowd as an example. Everyone thought it was a good idea, but the further the concept shifted along in development and away from the original engineer, the less people understood what a bug bounty program actually is. By the time it gets through legal, and marketing, and the executive team, it turns into a downside protection effort rather than quality/security improvement effort. I have to imagine this is pretty common in large organizations that keep their departments siloed off from one another, reducing collaboration.


Do you work.... where I work?

Because that sounds like where I work.


Yeah, I work there too. The weird little rock between Venus and Mars covered in bureaucrats and other insects?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: