back to article Don't collect bugs, invest in fly-spray says bug bounty operator

Kate Moussouris says security defenders should spend cash to acquire and build the tools of the bug hunting trade rather than dole out cash for warm bodies or endless zero day. The chief policy officer for bug bounty outfit Hacker One and former Microsoft security boffin says in new research that defenders need to catch up to …

  1. Anonymous Coward
    Happy

    It makes sense

    pay over and over to get the service, or pay once and fix yourself.

    Ah yeah the old CapEx vs Opex rearing it head again.

  2. amanfromMars 1 Silver badge

    The Shape of The Internet Of Things to Come ....

    "Incenting more eyes to look for security bugs will help drain the offense stockpile, which is true, especially in less mature software …however, if an organisation operating in the open, and focused on defence, offered six figure sums for vulnerabilities, regardless of whether the bounties are for mature software or not, this would … create perverse incentives, especially for less mature software.

    Such though is just the capitalist way, and easily corrupted and perverted and subverted to service and server a vast array of client bases which are invariably also always in competition with and in opposition to each other. Having all bases covered and provided for is a rich source of riches and quite the norm in those sectors which are drivering the virtual reality of media-related existences.

    And an organisation operating in the open, and focused on defence, and drivering such futures which are realised as easily manipulated media-related existences are worthy of demanding and receiving multi-million/billion figure sums for the vulnerabilities which can be seamlessly invisibly exploited and expanded upon stealthily to ensure and assure remote virtualised command and control of leading players and actions with ……. well, let us just call it in the Cyber Space Field Place with Secret Safe and Secure Intelligence Services, AI NEUKlearer HyperRadioProActive IT.

    And a little something for the Digital Marketplace too? Or do you imagine that would be evidence of that service being infiltrated and exploited by that which it needs to purchase in order for its hosts and interdependent and interindependent service providers to survive and prosper in a New Orderly World Order Program and Global Operating Devices Project.

  3. Anonymous Coward
    Anonymous Coward

    Or they could. like. right gud kode.

    1. amanfromMars 1 Silver badge

      Kool Running Hot Brains Needed for that APT ACT App, theodore.

      Or they could. like. right gud kode...... theodore

      Until such times as that happens, theodore, in all of the places and spaces that really matter and effectively driver the future, will their systems always be failing and falling over/booming and busting ever more revealingly destructively, and be under constant attack from considerably smarter forces against which they have no real practical or virtually secure defence. And to not engage with what might be considered the enemy destroying their systems and legacy applications, will beautifully hasten that progress and inevitable demise.

      "Tis only natural in the Greater Scheme of The Internet of Things with Virtual Machines that Pass the Turing Test.

      1. Charles 9

        Re: Kool Running Hot Brains Needed for that APT ACT App, theodore.

        "Until such times as that happens, theodore, in all of the places and spaces that really matter and effectively driver the future..."

        And that time will never come since humans are fallible, and the bad guys only have to be lucky once...

        As the article linked in the article notes, failure is unacceptable but also inevitable.

        1. amanfromMars 1 Silver badge

          So Be It and IT

          And that time will never come since humans are fallible, and the bad guys only have to be lucky once... .... Charles 9

          Please be hereby advised, Charles 9, in the fields of concern and areas of especial interest under discussion and the spotlight here, does luck play no part whatsoever. And do the bad guys only create ever increasingly destructive and disruptive problems for themselves.

          And who are the bad guys nowadays, thinking to control things badly with the supply and non-supply of monies, which is a kind of great idea but only if it can be done correctly and paper currency and bank account balance figures continue to be perceived of as being valuable and not just a vehicle for the passage of pretty printed paper for consumptive purchase of assets and essentials to the masses/pretty worthless glass beads to the natives? ........Meet The Secretive Group That Runs The World

          And is a great deal more of the following what we all have to look forward to as greater intelligence and shared secretive information brings down castles built on shifting sands and hopeless dreams ....... http://www.telegraph.co.uk/finance/economics/11538001/Mario-Draghi-attacked-at-start-of-ECB-press-conference.html ...... and when is main stream media going start reporting on the global scam that deludes and imprisons everyone with only a titter of wit? What on earth are the afeared of? The Truth? Or a wholly natural violent reaction from the masses to the lies that they have been feeding them since forever and a long time now, and all for the greater material benefit of a chosen few and a system which is corrupt and rigged?

          Does the internet and world wide webs and alternate media sources have to do everything?

          1. Destroy All Monsters Silver badge

            Re: So Be It and IT

            Does the internet and world wide webs and alternate media sources have to do everything?

            It is our only hope. But they don't dispense satchel charges, so something more may be needed.

            One way or the other, "it's happening" soon, fellow amanfrommars

  4. Destroy All Monsters Silver badge
    Paris Hilton

    Interesting...

    What kind of diagrammatic notation is that?

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like