Responding to Hackers: Vulnerability Disclosures and Bug Bounties

Listen to learn about differences between vulnerability disclosure policies (VDPs) and bug bounties, as well as PCI DSS post-disclosure obligations.

Updated:  
November 6, 2023

PCI Community Meeting North America Special Podcast Recording:

SecurityMetrics Podcast | 79

Responding to Hackers: Vulnerability Disclosures and Bug Bounties

Ethical hackers and cybercriminals are not the same thing, and it can be beneficial to establish a channel to communicate with hackers trying to alert you to vulnerabilities.

Ilona Cohen, Chief Legal and Policy Officer at Hacker One, and Harley Geiger, Counsel at Venable LLP, sit down with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) at the PCI Community Meeting North America to discuss:

  • Hackers vs. cybercriminals
  • Vulnerability disclosure policies (VDPs) vs. bug bounties
  • PCI DSS post-disclosure obligations

Resources:

Download our Guide to PCI Compliance! - https://www.securitymetrics.com/lp/pci/pci-guide

Download our Guide to HIPAA Compliance! - https://www.securitymetrics.com/lp/hipaa/hipaa-guide

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

Responding to Hackers: Vulnerability Disclosures and Bug Bounties Transcript

Hello, and welcome back to the Security Metrics Podcast. My name is Jen Stone. I'm one of the principal security analysts here at Security Metrics. And here at Security Metrics is in Portland.

We are, talking to a lot of the people who are participating in the PCI community meeting, for North America in Portland, Oregon. Very excited to have two guests with me today on a very interesting topic. And let me let me say the things. I'm gonna read it so I get it get it wrong.

Harley Geiger, counsel at Venable LLP, and Lana Cohen, chief legal and policy officer for HackerOne.

Welcome. Thank you so much. You wanna tell people a little bit about you and where you work, just a little background?

Sure, I'm happy to do so. But thank you really for inviting us. We're really happy to be here. So, yes, I'm Alana Cohen.

I am very proudly at HackerOne where we help create we help companies and the government establish vulnerability disclosure policies and bug bounties so that we can help identify vulnerabilities before cybercriminals exploit them. I got here in through a variety of different means, but I got my start in national security, and I was in the White House counsel's office for the Obama administration, and then also in as the general counsel of the office of management and budget where we handled quite a few, unfortunately, cyber breaches. Yeah. So it's really nice to be able to take that experience and and bring it to HackerOne where, you know, like I said, we we both help companies, but also help the government.

So I'm a very mission driven person, so it's really nice to be able to assist the government in that way.

Great. So thank you for for sitting down with me. Harley.

So I'm Harley Geiger, and I am an attorney with Venable LLP, where I focus on cybersecurity, incident management, and compliance. I also lead the hacking policy council, which is a group of companies and individual experts who work on vulnerability disclosure policies, bug bounties, penetration testing, and hacking law. And I got my start in the civil liberties community, actually, working on privacy and surveillance, and, worked on the Hill for a couple of years where I started working also on computer crime and cybersecurity, and then worked at Rapid7, a cybersecurity company in house for about seven years before joining the law firm.

Oh, well, terrific. So you guys have so much knowledge and experience. This is exciting to get to talk to you. We've tossed around the word hacker here several times already in this conversation.

And I just wanna tell you, I go to DEF CON every year, whether I like it or not. I do like it, but there's a lot of people. And so sometimes that's a little overwhelming. And one of the big topics that that is kind of evergreen there is people will call someone a hacker with a negative connotation, where a lot of people who consider themselves hackers do not consider a negative connotation.

And I was wondering if maybe you could kind of break down the difference between hackers and cybercriminals and maybe offer some clarity there.

Well, they both wear hoodies. Mhmm. The hackers and the cybercriminals. Okay.

That's valid.

They both think they're really cool.

They are.

They they do. All the hackers are. And, I mean, really, the so first of all, completely agree that there's there's an an important distinction. I think that there I I'm optimistic about the the the perception of hackers as not all being cybercriminals.

Right.

I think that is changing.

But I am also I I also go to DEF CON and you know, work with the with the community. Outside of the community, I still get surprised by how many people don't make that distinction Mhmm. And do attach fear to the word hacker.

Probably because of pop culture.

Yes. I think that's a lot of it.

They watched war games one too many times.

In the media.

Think the media, not just pop culture, I think when the media reports on these things Oh, uh-huh. There was a long period there where the media did not make that distinction.

Right.

Neither did law enforcement. Right? And so that that became something that I actually think the community has made a lot of progress on.

Oh, good.

Particularly as it relates to to government. But differences between the two, some important ones. One is that people who are hacking tend to do so for the purpose of strengthening security. Mhmm.

Right? And that that is their their end goal. Whereas cybercriminals in general, they want to be paid. Right?

Or they're they're intentionally causing some sort of a disruption because of another agenda like, you know, social activism, you know, or or even a nation state geopolitical agenda.

So number one, motivation. Mhmm. That can be kind of hard, though, to really discern.

Right? Do you how do you or can we read minds and know what really motivates people? You know, is that their intent? Or maybe some of them say what their intent is and their motivation.

Yep. And a number of them are accidental discoverers. Right? So another one though is if if you're a company and you're you're learning about a vulnerability or you're being contacted by a hacker, how are they talking to you?

Right? Are they Yeah. When are they going through a channel that you have established to have these kinds of conversations? We call those vulnerability disclosure policies.

Or are they reaching out on Twitter? Are deliberately not using the channel that you've set up? So the way that they've approached you. Another really important red flag is money.

In the end, if a cybercriminal has reached out to you, a lot of times what they want is funds.

The way that that comes up and the timing is important. So a lot of times, if you are a security researcher, it's not that you don't necessarily ask for money, but you'll probably do it after you've disclosed the vulnerability. You're not saying, pay me or I won't tell you or pay me or I'll exploit Right? You'll disclose it and then you'll say, hey, I could use five hundred bucks. And that's not necessarily wrong. It's not best practice to pay them, but that that the timing is is what matters.

Okay. Whether there's an or else or not attack.

Exactly. If there's an or else, then it looks like extortion. Mhmm. And then lastly, there's there are other differences, but these are three big ones, is whether or not the the hacker has exfiltrated way more data than they need or has disrupted your system or has caused some other kind of harm. That is usually a big red flag.

So he talked an awful lot about vulnerability disclosure policies, VDPs.

Is this something everybody should have? Tell me, what are these? So vulnerability disclosure policies are absolutely something everyone should have, and there's a growing recognition that that's just an industry best practice now.

It's mandated for government agencies in the US. In Europe, it's about to be mandated for a much broader community, and it's something that many customers ultimately do have because they see it as vital.

In order to be able to I mean, this research is happening anyway. Right? Security researchers are already looking at your system. Mhmm.

The question is, do you want to have a program that allows you to accept that information, deal with it, mitigate it, and then, you know, interact with the hacker in a positive light? Mhmm. Or are you willing to sort of find out like everybody else on Twitter? Those, in my view, that's in my view the the sort of the choice here about whether or not you have a VDP or not.

Okay. So what does a what does a VDP look like?

A VDP can is essentially a program where you this is important, actually. It's a program where you invite the public to report to you. Okay. But you can't stop there. If you just invite the public to report a vulnerability to you, and you ignore that, or you don't have a process by which you communicate with a security researcher who reported it Mhmm. Then you do so at your peril.

You really do wanna have both the mechanism to accept the information, but then on the back end, you really do need inform you need the ability to take the information in, assess it, assess the criticality of it, respond to it, mitigate it.

Mhmm.

And then, you need to be able to have a transparent sort of timeline and communication with the security researcher. So they know that you're taking their information seriously. Especially if you have a vulnerability disclosure policy instead of a bug bounty where there's payment involved, you do really wanna make sure that you're giving the hacker the credit Mhmm. For reporting it to you. If you haven't if you're not giving a financial incentive, you do wanna at least give them the credit that they might want to use with the rest of the community.

Okay.

And so transparent communications is really vital. Alright. So can you give me examples of of people who are doing a good job with the VDP? Well, the, HackerOne obviously runs a number of VDPs for both the government entities as well as for, for customers.

One of our longest standing customers is the Department of Defense. And they just announced the forty seven thousand vulnerabilities reported through the system since twenty sixteen.

So they're using you as a third party for their So we host the the Department of Defense's program.

Mhmm. And so and, you know, we marry up the a customer with we have one point seven million hackers Mhmm. Who ultimately have signed up with HackerOne. So we marry the two together and encourage reports through our system if they're a customer of ours. But I don't think I just I don't wanna worry off any potential customers who might be thinking of a VDP. You're not gonna get forty seven thousand vulnerability reports that you have to Sounds a little overwhelming. People are just pretty excited to be able to say that they hacked the Pentagon.

Oh, I can imagine.

So that's that's in part why they've had that success. But we really have success from multiple of our customers. We have, you know, Zoom and Goldman Sachs and many of the financial services many of the folks in the financial services sector, Zebra, Visa, they have both. Although, they also have bug bounty programs, which I'm happy to also get into.

Well and you were mentioning something earlier, you know, what something about when and the money and how they ask.

Is that really the root of the difference between VDP and a bug bounty? Or is it the difference between a bug bounty and a extortion?

Like, what is There are several differences.

But, yes, money is is is a big one. Alright. So for, vulnerability disclosure policies, like Alana said, it is a it is a mechanism for receiving processing and and mitigating and communicating about vulnerabilities. And generally, no money is involved.

Bug bounties, you are not just inviting folks to to hack something. There's also the promise of payment if they find a vulnerability. And that that payment will depend on the significance of the vulnerability. But some of the other differences are a vulnerability disclosure policy is often something that organizations will sort of establish and it'll be present over a very long period of time.

And it is just a foundational practice that if you find something, see something, say something. Bug bounties tend to be more limited in terms of their time and their scope or at least you can make it that way. So you have more control just as a matter of practice over what is going to be, what you are inviting people to hack. So you could say for example, you are invited to hack our products but you're not invited to hack our customer profiles. Something like that.

Or we are going to have a bug bounty program that will last for a year or even a couple nights as just a live hacking event and not longer. So the scope tends to be different for bug bounties than for vulnerability disclosure policies as well.

Okay. Interesting. You had some good VDP examples. Do you also have maybe some bug bounty examples?

Yeah. I mean, we actually Harley mentioned, some of our live hacking events. Those have traditionally yielded just remarkable results. We just did one in London for Zoom and for Salesforce, and they were extremely happy with the results that they get.

This is like we invite a little elite group of hackers to come in and just have a dedicated twenty four, forty eight hours in which they're looking for everything and anything that they can find in the system, and then report that out. But more often, our our bug bounty programs are much longer in time. You know, there's no it's often not time bound at all, actually. Okay.

They want they want the information whenever the information becomes available to them. Right? And as the as the company rolls out new products Mhmm. They're ultimately interested in continuing to get vulnerability data.

Okay. And if they host a if they have the if a customer had a program on HackerOne, a bug bounty program, we would help them assess sort of how much they should pay for a vulnerability.

You don't wanna be totally out of the norm. Again, if somebody asks for something for a moderately, you know or something that's not critical Mhmm. Then I think, you know, you know that it's not necessarily in good faith. So you wanna make sure that you're paying out a standard amount for the type of vulnerability and the severity.

Okay.

A couple other good differences that you just brought up about asking, right? So asking researchers to hack your products, your systems, know. The vulnerability disclosure policies don't always have that authorization. In fact, a fair number of them don't.

They'll just say, if you find a vulnerability, this is where to disclose it. But they don't say, you are hereby authorized to look for vulnerabilities in our system. But some vulnerability disclosure policies do. The federal government right now, all civilian agencies are required to have a vulnerability disclosure policy and all those civilian agencies do in fact provide some authorization to look for vulnerabilities and to disclose them.

Bug bounty programs always give that authorization.

It is, that's part of the setup. And it's usually pretty clearly described what the scope of your authorization is. VDPs, it can vary.

Interesting. And so when we take this back to the PCI world, disclosure of any kind wasn't really defined in 3.2.1. But four point zero is full of new and exciting things. I'm not gonna make you like, I'm sure you have not memorized this language.

No. We didn't.

Oh, did you? Maybe Harley did. Did you really?

Well, had we presented on it this morning.

Yeah. We did.

Oh, okay. Well, tell me about the the new requirement then in four point o for this.

Well, there's a couple things. So there's a there there's a requirement within four point o for multi tenant service providers. Yeah. And so for and and I I frankly, I did not know what those were. I had to look them up. But they are things like SaaS companies Yes.

Web hosting providers and and other like, lot of cloud service And honestly, there's a lot of people who don't know what what is meant by multi tenant, and so Right.

Yeah. It's it's not just you. This is something that there's a lot of people a lot of merchants never get to the eight point one requirements because they're not multi tenant. It's not super common. But please continue.

Oh, well so there so what four point o says about that is that those multi tenant service providers have to have a way of allowing their customers to disclose vulnerabilities or cyber security incidents to the service provider. Right. And this is kind of a form of VDP.

But it's not, you know, when we talk about a vulnerability disclosure policy the way that we have been, it's not really open to the public, right? What it requires is just their customers to be able to disclose that, which is, I mean, also like pretty common standards language, you know, contract language, but not quite a VDP. Now, that being said, I mean, you could have a public facing vulnerability disclosure policy that is that your customers can also use. You could fulfill it that way. But that's one of those areas that I think PCI, believe it or not, is not necessarily keeping up with some of the other developments that we see in best practices and regulation, which are increasingly tilting towards requiring vulnerability disclosure policies as matter of best practice. Now, I also learned that we have no idea otherwise, as a part of doing our our presentation this morning, that there are other, standards that PCI does that, actually do, much more explicitly require a VDP.

Beyond the PCI DSS Exactly.

Which is the one that, you know, most of us have heard of because it's merchant related, so there's a lot of them.

Yes.

But there's like you said, there's a lot of other standards put forward through PCI.

They've been busy. Yeah.

But there's and again, I sound like I know this really, really well, but it's really because of this presentation that that I now know this. But the the mobile payment on COTS Mhmm. Or MPOC standard Mhmm.

As well as the three d s I don't know what the three d s means, but three d s secure software You mean three d s.

When I think three d s, I think of the Nintendo system.

So is that what I'm talking about?

Yeah. Absolutely. No.

Yeah. Just the Nintendo system has to have a VDP.

So the but mPOC and three d s s s s k both require organizations to have a public facing vulnerability disclosure process. Okay. So so they have to be able to intake vulnerability information or cyber incident information from a variety of sources and it can't be It has to be protected. Like it can't just be an email address. It has to be without more encryption. Otherwise, that's not sufficient.

Harley mentioned that there are requirements to have VDPs and that the government is one of them. And it's it's hard to imagine that the government could be ahead of the curve on anyone in this area. But in fact, in twenty twenty, they issued this guidance that said all government agencies have to have VDPs or vulnerability disclosure policies. So we're hoping that maybe I know we're still we're just rolling out four point o here in in in this next year, but we do hope maybe that four point one could potentially have that same standard. And that also, before that is ultimately accomplished, that perhaps PCI could issue some guidance that specifies the importance of VDPs and the way that one could ultimately roll that out.

And you know, one of the things that I've noticed about PCI, the Standards Council and the development of standards, is that over the recent years, a lot more involvement has been requested. Help us develop this. Help us know what's important. And so maybe by raising awareness and bringing that conversation to the council, that's something that could be considered because we don't all know everything. And so living in the world that you live in, where you're thinking of these things all the time, it might help frame that and bring that forward to the next version.

Yeah, and we saw that actually, which is, you know, a testament to the council that they work with, you know, they collaborate and partner with industry to make sure that they are getting out, appropriate standards to the community. We saw that with pen testing. That was an like a great partnership with industry and so we're hoping we'll have something, be able to do something similar here.

Yeah. So you said there were a couple.

There is one more.

Okay.

Yes.

So in, there's another part of DSS four point o, which has, it's a control family six.

So on vulnerability management and there is a control within that that requires organizations to have a means of learning about new vulnerabilities. Right. And there again, it really prescribe a means but it does mention guidance that bug bounty programs are one way for organizations to learn about new vulnerabilities. Right. And I would add onto that, you know bug bounty programs as well as vulnerability disclosure policies, both of them are ways to learn about vulnerabilities.

Know, there again, like that's a good area I think for clarification and guidance. But yeah, so it's, for the first time, you know, these these concepts are being sprinkled into PCI DSS.

Mhmm.

And they're more they're more explicit in some of their other program standards.

And and so as a QSA, really conversing with customers about the difference between a bug bounty program or or how you disclose all these, this has not been part of the standard conversation.

And so I know that I have been behind on the VDP concept and how it how it compares to a bug bounty program or, you know, other ways to disclose, from a PCI perspective. I know that in, HIPAA, there, of course, is breach disclosures that are very clear, but that is a law as opposed to a standard, and, which I I I wonder if that maybe affects things in in certain ways. But with your experience in in in Washington, D. C. And the development of laws and being part of that, what do you see coming down the pipe in terms of laws and disclosure necessity across the board, not just in PCI.

Oh, absolutely. Yeah. You're this is, as I mentioned, just a commonly accepted best practice now. VDPs are required for the federal government, and as a result, we're starting to see interest among members of congress to make VDPs mandatory in a broader group.

So for in the IoT Cybersecurity Act, they they mandated VDPs for for certain contractors under that bill. But we just saw congresswoman Mace from South Carolina introduce legislation. HackerOne worked as a subject matter expert with her office on this bill, that would mandate, VDPs for all federal contractors. And that's because it's really important if you're going to shore up the security of the federal systems, you really need to make sure that there are appropriate controls and and programs in place to to shore up any contractor that has access to those systems since that's a pretty easy entry point.

So it really is to in order to make sure that both the contractors themselves are safer, but also for the entire federal eco ecosystem.

Okay. So a lot of us know there are breach ops obligations. If there's an actual breach and there is a you know, information has been lost, there's obligations that have to happen. But sometimes we don't focus on post vulnerability disclosure obligations. Can you speak to that at all?

Sure.

So there's a few distinctions here. So when we talk about breaches, often what we mean is a data breach. And when we talk about data breaches, often what we mean is personal information. And so yes, every state as well as a lot of regulated industries, finance, healthcare, what they're focused on with breach notification is personal information.

But there are increasingly more regulations and requirements around reporting cyber incidents even if personal information is not involved, as well as sometimes obligations on what to do if a vulnerability is found or if a vulnerability is exploited. So if a vulnerability has been exploited, that sometimes will meet the definition of cyber incident and you have to report that incident, sort of depending on what industry you're in. There are a growing patchwork of cyber incident reporting obligations. So the financial sector has all of them through their regulators. NYDFS has one.

The Securities and Exchange Commission just released a rule that requires cyber incident reporting. So it's There's quite a lot of them. The timelines range from sometimes within a matter of hours that you have to report to several days, like four days. So it is an active discussion right now how to make those a bit more consistent, more standardized.

Part of the issue though is that we're seeing this also happen internationally. Right. So Europe has increasingly cyber incident reporting obligations.

And there is, as you might imagine, there's a lot of contention around at what point does the presence of a vulnerability or even an attempt to exploit the vulnerability, should that really be something that we report every time? Wouldn't that fill the reporting system with too many reports, a bunch garbage notifications?

If a vulnerability is exploited, does it have to be bad enough to report? So that trigger is under hot contention. But I think the takeaway should be that organizations should consult with their legal counsel to help make that distinction. Their legal counsel should be working with the security team to help assess the severity of the incident, see whether or not it triggers that legal obligation. So not just about data breaches anymore.

Right, right. But it seems like a lot. I mean, one organization, let's say you have an ecommerce business, it seems like they're hit with all of these requirements and legal things. How do they comply and how do they know what applies? And like you said, that's what counsel is for. But in your view, is there any foreseeable future that kind of brings these cybersecurity regulations and privacy regulations together in a more cohesive manner, or is it really just a bit of chaos right now?

I think it's still a patchwork, and I think it'll remain a patchwork for some period of time.

Mean, both because we have you know, the states proceeding in the way that they will proceed and federal government doing its own thing. And then, of course, you have the EU, as Harley mentioned, right now, the cyber resilience act, which is in draft form but pretty close to being final, has certain reporting obligations that are in contrast with, you know, what the US might require. So I think you need to make sure that you hire very good cybersecurity lawyers like Harley and that you are paying close attention to the different standards.

Yes, Jen. The future is chaos.

I'm so relieved to hear that. Right.

There is.

But it so I what what Alana I completely agree with what Alana said.

I think the idea of Especially the part about him being a good lawyer.

Yeah. Yeah. Yeah. That's that's fantastic.

The federal privacy federal privacy legislation has been, under discussion for, like, two decades Yeah.

Now. And at at decades ago when we were first started talking about this, I think the argument was Congress you should do this because privacy is gonna be a problem and we don't wanna have a patchwork of state laws.

And recall at the time, industry was reluctant about whether or not this was a good idea. That now the dynamic has changed, industry wants a comprehensive federal privacy law and it is Congress that is reluctant to pass something because now the states, their constituents have all now voted, they've all acted. Mhmm. And so I think that it's gonna be very difficult to see a comprehensive privacy law that is passed by Congress that that is really meaningful.

On cybersecurity Well, it's difficult to have any meaningful legislation in congress these days that has, like, a a real holistic approach because it's just not what they're focused on right now.

So it's And and and getting everybody on the same page and even what words mean.

So, I'm part of a private partnership in the healthcare space. And we spent weeks discussing what's the definition of privacy and what's the definition of security. And when you don't even have a foundational common set of language around something that starting place, it makes it difficult to bring laws into it because what do these words mean? How do we look at them?

And is there even a foundation for a one size fits all? I mean, that's one of the reasons I do love the NIST standards. I think they've done and continue to do just an excellent job in creating an understanding of a comprehensive cybersecurity program. Absolutely.

But it can be difficult to know exactly what do we disclose and when and how.

And it's hard to know where to look.

Right? I mean, so you mentioned NIST on VDP actually because the government mandated it for itself. They turned to NIST and said, tell us what a good VDP looks like.

Mhmm.

Give us the components of that. And now they've done that, and the, you know, there are many in the industry who are using that as a reference point. The legislation that I mentioned earlier, the draft legislation, it would ultimately require that any VDP policy that is adopted by a federal contractor follows that standard because it's a best practice.

It is. And it seems sensible to to to take that approach. Then, of course, you add Europe on top of that. You know?

So because NIST really is a a US focused US developed standard, although there are places beyond the US that use it. Yeah. But there are other places that say, no, we wanna use a European standard. You know?

So you get the twenty seven thousand ones and and beyond, you know, those those sets of things and and others.

Finding a common way to approach these things, I think it's gonna take a lot.

I think on vulnerability disclosure policies, we do have a couple sets of popular ISO standards that Europe and the United States seem to follow as best practices, including NIST. NIST came out recently with their publication on guidelines for vulnerability disclosure policies for federal agencies and they referenced those standards. The legislation that Alana just mentioned references those standards. And Europe uses them also.

I think where we see a lot more divergence is actually in other areas outside of vulnerability disclosure policies. Oh, interesting. And if I, you know, for your listeners, if you're not paying attention to the Cyber Resilience Act, should really pay attention to the Cyber Resilience Act.

That I think is gonna have a GDPR like effect Okay.

On cybersecurity where we will be affected by it here in the United States because it is an extra territorial application and it is really comprehensive and there are parts of it that are good, I think from our perspective. So they they require vulnerability disclosure policies, which we think is good for the ecosystem. And there are parts of it which are very troubling, including the idea that you have to report any actively exploited vulnerability to a variety of EU government agencies, including prior to mitigation.

It's a rolling list of software packages That stress people out. Software packages that don't yet have a mitigation that could be shared depending on the final version but it's pretty advanced but it could be shared with dozens of EU government agencies with not a lot of restriction or oversight in terms of how they're used.

Is why people would be stressed out about it because if that gets out then the bad guys go, oh hey look we know how to get in there and actively exploit this vulnerability.

And it makes the government agencies a very rich target.

Yes. And it's a very tempting thing for the government agencies to use.

Well, this has been hefty and somewhat depressing as But the question you asked though had a positive answer because you said what about the divergent standards?

And here, actually, for once, they're they're pretty consistent.

Well, I good point. I really appreciate I'm trying to find the silver lining for you. I'm guessing a lot of your I don't wanna black pill everybody.

I'm guessing a lot of your podcasts have some pretty, you know, serious news for folks. Yeah.

At least we have something positive.

Yeah. We have a wide range of people who listen for various reasons to various topics. I think this was is going to be something that a lot of people wanna know more about. So I really appreciate you coming and talking to me. But before we wrap it up, is there anything we missed or anything you wanna add on? Anything exciting coming or anything?

I I think we just covered some of the something you know, obviously, I consider exciting.

But but on on the positivity. Right? So I I do think that it is very positive the the way that security researchers are being integrated into, I I think, the security landscape. Yeah. And I think that is a sea change from where we were ten years ago or so.

Mhmm.

You know the way that we kicked off this conversation was how people are sometimes afraid and don't always make the distinction but I think that there's been a great deal of improvement in that area. I think that researchers, like their contributions are increasingly valued. And I think that we as society rely on them to some extent for sort of independent market surveillance of products.

I think the trick for a lot of companies, lot of organizations that are on the receiving end of that research is figuring out ways to work with them. And that's really what VDPs and bug bounties are about.

Excellent. I'll leave you with one statistic, if I may. Sure. Which is that the average payout for a bounty on our system is about one thousand dollars whereas the average cost of a breach is about four and a half million. So I would just encourage your listeners to please consider that cost benefit analysis. And then when they're done considering it, they can call HackerOne.

HackerOne. Okay. Yeah. HackerOne has an excellent reputation. I'm so glad that you were able to to be here today. And and you as well, Harley, thank you very much for your time.

Thank you so much for inviting us.

Yeah. Thank you.

Thanks for watching. To watch more episodes of SecurityMetrics podcast, click on the box on the left. If you prefer to listen to this podcast, it's on all your favorite podcast platforms. See you on the slopes.