I have seen the future, and it is bug bounties
Every now and then I see something on a blog or Twitter about how you can’t replace a pen test with a bug bounty. For a long time I agreed with this, but I’ve recently changed my mind. I know this isn’t a super popular opinion (yet), and I don’t think either side of this argument is exactly right. Fundamentally the future of looking for issues will not be a pen test. They won’t really be bug bounties either, but I’m going to predict pen testing will evolve into what we currently call bug bounties. ...