|
|
|
|
|
by ericalexander0
1046 days ago
|
|
You're better off doing a private bug bounty through bug crowd or hackerone. Pentests are point in time assessments. Usually with one to two testers, with limited scopes of expertise. Bug bounties can bring in hundreds of testers with a wide breadth of expertise that continuously test. |
|
In the beginning we got a lot of false positives. Things like people creating two accounts and giving them both access to the same resource (a common task in our platform), and filing that as a bug. Probably half of our reports were like this, the other half were real bugs.
Over time the reports have dropped off, but still trickle in every now and again.
I definitely think the bug bounty was much more effective than the pentest at discovering vulnerabilities.