The Uber Breach: Extortion Does Not Equal Bug Bounty
bugcrowd.com | blog | #bug-bounty | #extortion | #data-breach | #ethics | #disclosure | #uber-breach
Summary
Bugcrowd CSO David Baker clarifies that bounties pay for in-scope vulnerability findings, while Uber's concealed $100,000 payment was extortion, and failing to report the breach violated the law.
- Published
- Collected
Skip to content