← Back to context

Comment by manigandham

8 years ago

Why? Many can help find problems without having to be full-time, that's the point of crowd-sourcing with payouts.

Because you'll make much more working for people who specifically hire you instead of doing a bunch of risky work on spec.

  • The point of bug bounties isn't to attract the interest of people who are working to find bugs. It's to make sure that if someone is finding bugs for fun or stumbles over bugs by accident, it's worth their time to report the bugs.

  • An actual pentest would include (I'm assuming) all sorts of NDA's and legal contracts and stuff, all fine if you work in the industry but if you're a bored hobbyist like me, bug bounties are a fun way to try and make a few dollars.