Deri

mirror.xyz · riptide · 4 hours ago · opinion
0 net
AI Summary

A critique of bug bounty program practices, contrasting good practices (fair and timely payments) with bad practices (ignoring disclosures, delayed payments, underpaid bounties) in the context of DeFi protocol security.

Entities
Balancer riptide
About Activity Share Home Explore New post Dashboard Newsletter Search... Ctrl + K riptide Sign in white hat hacking for fun and profit More from riptide riptide Feb 1 Balancer’s Bountiful Merkle Orchard Security & Bounties Let’s talk about bounties for a bit ... How to run a good bug bounty program: 1) the protocol is a good actor w/ regard to paying bounty hunters fairly and timely 2) bounty amount represents a fair reward compared to the amount of funds at risk How to run a bad bug bounty program: *1) bug is disclosed to protocol and follow-up emails by hacker are ignored/no timely responses 2) payments are confirmed but delayed for weeks/months 3) actual bounty paid is less than advertise... View more About Activity Share More from riptide riptide Feb 1 Balancer’s Bountiful Merkle Orchard Security & Bounties Let’s talk about bounties for a bit ... How to run a good bug bounty program: 1) the protocol is a good actor w/ regard to paying bounty hunters fairly and timely 2) bounty amount represents a fair reward compared to the amount of funds at risk How to run a bad bug bounty program: *1) bug is disclosed to protocol and follow-up emails by hacker are ignored/no timely responses 2) payments are confirmed but delayed for weeks/months 3) actual bounty paid is less than advertise... View more white hat hacking for fun and profit Subscribe Subscribe Subscribe to riptide Subscribe to riptide Subscribe Subscribe <100 subscribers <100 subscribers