Josh and Kurt talk to Jill MonĂ©-Corallo about GitHub’s bug bounty and product security team. It’s a treat to discuss bug bounties with someone who is managing a very large bug bounty for one of the most important web sites in the world of software today. Show Notes
Tag Archives: bug bounty
Episode 337 – Security patches are getting worse – Dustin Childs from ZDI tells us why
Josh and Kurt talk to Dustin Childs about the recent ZDI Black Hat talk where they discovered the current trend of security patches not actually fixing the security problem. We talk about what this problem means. Why is it happening, and what ZDI is doing to try nudge the industry in the right direction. ShowContinue reading “Episode 337 – Security patches are getting worse – Dustin Childs from ZDI tells us why”
Episode 291 – Everyone sucks at vulnerability disclosure
Josh and Kurt talk about recent events around Apple and Microsoft disclosing security vulnerabilities. Microsoft usually does a good job, but Apple has a long history of not having a great bug bounty or vulnerability disclosure policy. None of this is simple, but hopefully you’ll have some fun and learn a bit about the wholeContinue reading “Episode 291 – Everyone sucks at vulnerability disclosure”