|
|
|
|
|
by tptacek
338 days ago
|
|
My understanding is that all Bugcrowd bounties do by default. You can shame it all you want, but you can also just publish your bugs directly. Nobody has to use the Bugcrowd platform. You don't even have to wait 45 days; I don't buy these "CERT/CC" rules. |
|
Even among 3rd party platforms, of which there are several bigs, the NDAs are not a platform requirement, just an option for participating firms.
NDAs are not the norm. Don't mislead people who would otherwise get into this game with non-issues they need not worry over.