错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Bug Bounties: Ethical and Legal Aspects

  • João Paulo Magalhães

摘要

Bug bounty programs are a new approach to pen-testing. Through them, organisations are willing to test their products taking advantage of hackers spread all over the world. So, the number of vulnerabilities found increases and the cost of detecting them becomes lower. To maintain some control over what hackers can do, organisations specify a set of rules. Through these rules, organisations try to limit the actions to be performed and to give confidence to ethical hackers conduct activities that are typically illegal without being worried with the risk of legal violations. This article presents an analysis of the current state of bug bounty programs. The analysis focuses on economic, ethical, and legal aspects and highlights several problems related to these aspects. Given the current state of these programs, it is important that national bodies responsible for cybersecurity, address the challenges imposed by these programs. National and international rules are needed to both ethically and legally protect the parties and contribute to regulate an activity that many still consider illegal. Without that, a set of alternative solutions to “legalize” them in an ad-hoc and unclear way will continue to proliferate creating ethical and legal problems.