Hacker News new | past | comments | ask | show | jobs | submit login

This is why internal bug bounties should pay cash. Most orgs don't even have one.



We have an interal bug bounty program! But it's more of a retainer when you think about it. We basically transfer a six figure dollar amount, in 12 monthly installments, to our developers. Then in return when they find a bug they bring it to attention and fix it. It works pretty well!!


It would be interesting to have a dedicated bug fixer whose only job was hunting bugs. No meetings, no scrum, no design docs, etc.


Kind of like a red team.


Which Apple has, of course.


Ha. If you happen to know of a red team that doesn't have to still go to meetings and write documentation, please let me know so I can switch employers. :)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: