Bug Bounty Logistics and Legalities: Your Questions Answered

12
Crowdsourced Cybersecurity Bug Hunting and the Law: Your Questions Answered Jim Denaro + Casey Ellis

Transcript of Bug Bounty Logistics and Legalities: Your Questions Answered

Page 1: Bug Bounty Logistics and Legalities: Your Questions Answered

Crowdsourced Cybersecurity

Bug Hunting and the Law: Your Questions AnsweredJim Denaro + Casey Ellis

Page 2: Bug Bounty Logistics and Legalities: Your Questions Answered

Speakers2

Casey EllisFounder & CEO, Bugcrowd

An innovator in crowdsourced security testing for the enterprise, Bugcrowd harnesses the power of more than 29,000 security researchers to surface critical software vulnerabilities. Bugcrowd provides a range of vulnerability disclosure and bug bounty programs that allow organizations to commission a customized security testing program that fits their needs.

James DenaroAttorney, Founder of Cipher Law

CipherLaw is a high-technology law firm providing strategic counseling to innovators in information security and defense technologies, including C4ISR (command, control, communications, computers, intelligence, surveillance and reconnaissance). With offices in Washington, DC and Los Gatos, California, we provide counseling on intellectual property, patent, contract, transactional, and litigation matters.

Bug Hunting and the Law: Your Questions Answered +1 415 867 5351 [email protected]

Page 3: Bug Bounty Logistics and Legalities: Your Questions Answered

Bug Hunting and the Law: Your Questions Answered

Outline

• Introductions

• Current State of Cyberlaw • Legal Questions & Concerns that come up with Security Researchers

• FAQs • The crowd • Liability • Compliance

3

Page 4: Bug Bounty Logistics and Legalities: Your Questions Answered

Bug Hunting and the Law: Your Questions Answered +1 415 867 5351 [email protected]

4

Risk and reward

Page 5: Bug Bounty Logistics and Legalities: Your Questions Answered

Bug Hunting and the Law: Your Questions Answered +1 415 867 5351 [email protected]

The Foundation:

Bounty Brief:• Scope • Out of Scope • Rules • Invitation

= Contract

5

Page 6: Bug Bounty Logistics and Legalities: Your Questions Answered

Bug Hunting and the Law: Your Questions Answered +1 415 867 5351 [email protected]

6

Regulation

Page 7: Bug Bounty Logistics and Legalities: Your Questions Answered

Bug Hunting and the Law: Your Questions Answered +1 415 867 5351 [email protected]

FAQs

Page 8: Bug Bounty Logistics and Legalities: Your Questions Answered

Bug Hunting and the Law: Your Questions Answered +1 415 867 5351 [email protected]

Questions about the Crowd

29,000 Hackers, 112 Countries Represented, Varying skill level & expertise

FAQs:• Rules and Policies • Contracts & NDAs • Rogue Hackers? • Public Disclosure Incidents

*Most important thing to remember - It’s not them against you, but them and you

8

Page 9: Bug Bounty Logistics and Legalities: Your Questions Answered

Bug Hunting and the Law: Your Questions Answered +1 415 867 5351 [email protected]

Liability Concerns

FAQs: • Who is liable for security researchers? • Who is held liable for any damages incurred

from bad behavior? • Personal liability?

9

Page 10: Bug Bounty Logistics and Legalities: Your Questions Answered

Bug Hunting and the Law: Your Questions Answered +1 415 867 5351 [email protected]

Compliance Questions

Current compliance guidelines impacting cybersecurity: • PCI • HIPPA • Safe Harbor

Bugcrowd’s Response • Private Programs

• More controlled environment • Elite Researchers

10

Page 11: Bug Bounty Logistics and Legalities: Your Questions Answered

QUESTIONS?

Bug Hunting and the Law: Your Questions Answered +1 415 867 5351 [email protected]

Page 12: Bug Bounty Logistics and Legalities: Your Questions Answered

Crowdsourced Cybersecurity