You are viewing a single comment's thread from:

RE: Who Hacks The Hackers? Binance Places $250K Bounty On Hackers, $10M Fund

in #binance7 years ago (edited)

I suspect such a campaign will provide no real actionable intelligence. Even if exchange customers were trained security experts (which they are not)

I think you got it wrong there. There's a fair amount of #infosec people trading cryptos. Very few would use the same aliases in this environment as the ones they use in their respective security research areas, it's a bad opsec to inform the bad guys about your financial assets and habits. Infosec researchers are targeted on a daily basis as it is.

But... Having said that, having a bounty as an incentive for the bad guys to snitch on one another (because seriously, who else would have that kind of information, right?), that might be like opening a can of worms...

Akin to the "hack back" scenario which harms more than it helps.

I'd rather see @binanceexchange invest that amount of money on a bug bounty program, that would be a healthier move. I guarantee it would be an instant success on platforms like hackerone and bugcrowd. If Binance's problem is the lack of expertise in managing such programs, those platforms could manage the bounty programs for them. (rather, would, that's what they do, mostly)

So my argument is more on the side of ignorance about today's infosec environment and procedures, rather than it being solely a PR move, and I do agree with you, it's not the best one at that!

I'd love to hear what @binanceexchange has to say about the "head hunting bounty" versus "bug bounty" issue, to understand their motives a bit, though.