Hacker News new | ask | show | jobs
by scoot 890 days ago
No. The companies offering bug bounties have already done more than the bare minimum. Finding a vulnerability for a bug bounty requires actual work.
2 comments

this seems to be airing a frustration that has moved beyond accuracy in the process, companies offering bug bounties may have done the bare minimum at one point in time but every production push they do changes that, and potentially reintroduces simple scannable vulnerabilities.
That's fair. We get numerous reports from script kiddies reporting "vulnerabilities" that aren't, because they don't understand the tool that they're running, or the output that it produces, or why it isn't relevant. It's possible that they catch a known issue, but the reality is that the majority have no idea what they're doing.
We did test it on Bug Bounty targets (see article) and found 2.5% of programs to suffer from at least one of these issues.