HN user

infosectosser

44 karma
Posts2
Comments4
View on HN

I head infosec for a “Series A - C” B2B company and a fairly standard request from a potential customer is to see not only our own penetration test reports but third party penetration test results, as well. As a result, we run automated pen tests on weekends and before major releases. We also work with an application security firm every 6-12 months. For what it’s worth, we don’t do anything nearly as intense as defense contracting or handling financial info.

That said, I liked the article - thanks for sharing.

I would guess it is precisely because BugCrowd is more expensive. They offer a managed program where BugCrowd's employees validate bug reports for participating companies. Speaking from experience, that process can become very time-consuming.

I'm responsible for information security at one of the other startups listed on BugSheet. As a heads-up, you're going to want to ask bugcrowd.com to remove your company from their list [1], also. We saw a pretty steep increase in the number of daily reports when first listed (4-5/day to >30/day) and it appears someone recently added your company to their site.

I'll also echo what droopybuns stated - creating templates that can address preliminary communication (duplicates, request more info, accept, etc.) will greatly reduce the amount of time you feel as though you are wasting. Some people I know tend to ignore the crazy ones but I generally prefer the "kill them with kindness" approach. One email explaining that you do appreciate the time they spent trying to help secure your site can do a lot to prevent harassment and potential bad press.

Best of luck - responsible disclosure programs are never fun for the person sifting through the reports but once in a while they do expose actual vulnerabilities and on those days, I'm happy we do it.

[1] https://bugcrowd.com/list-of-bug-bounty-programs