Joshua Rogers on his bug bounty experiences in 2025.

Positive for , kafka-esque for all others mentioned. ‚BugCrowd‘ seems to a typical level-1 support company living on denials.

(Joshua also reported on Apache and pbly other projects where he could talk to the maintainers. I take here as an example for FOSS projects interested in actually securing things.)

joshua.hu/2025-bug-bounty-stor

0

If you have a fediverse account, you can quote this note from your own instance. Search https://chaos.social/users/icing/statuses/115767775527620907 on your instance and quote it. (Note that quoting is not supported in Mastodon.)