Skip to content

Commit

Permalink
lingering uncommitted changes
Browse files Browse the repository at this point in the history
  • Loading branch information
ascott1 committed Mar 23, 2017
1 parent ac401f8 commit 44f048f
Show file tree
Hide file tree
Showing 2 changed files with 1 addition and 6 deletions.
Binary file removed web-apps-for-everyone/img/lie-fi.jpg
Binary file not shown.
7 changes: 1 addition & 6 deletions web-apps-privacy-security/04-security.md
Original file line number Diff line number Diff line change
Expand Up @@ -364,12 +364,7 @@ Developer Jonathan Rudenberg's post [Security Disclosure Policy Best Practices](
5. Don't place blame on teammates or employees.
6. Alert customers and inform them of the remediation steps.

As part of this process, you may want to offer a bug bounty for security researchers that discover vulnerabilities. The site BugCrowd has compiled a list of [bug bounty programs](https://bugcrowd.com/list-of-bug-bounty-programs/) that can serve as exemplars. Some well known sites that offer bug bounties are:

- [Facebook](https://www.facebook.com/whitehat/bounty/)
- [Google](https://www.google.com/about/appsecurity/reward-program/)
- [GitHub](https://bounty.github.com/)
- [Mozilla](https://www.mozilla.org/en-US/security/bug-bounty/)
As part of this process, you may want to offer a bug bounty for security researchers that discover vulnerabilities. The site BugCrowd has compiled a list of [bug bounty programs](https://bugcrowd.com/list-of-bug-bounty-programs/) that can serve as exemplars. Some well known sites that offer bug bounties include [Facebook](https://www.facebook.com/whitehat/bounty/), [Google](https://www.google.com/about/appsecurity/reward-program/), [GitHub](https://bounty.github.com/), and [Mozilla](https://www.mozilla.org/en-US/security/bug-bounty/). Recently the United States Department of Defense has even gotten in on the action, launching the [Hack the Pentagon](http://www.defense.gov/News/News-Releases/News-Release-View/Article/684106/statement-by-pentagon-press-secretary-peter-cook-on-dods-hack-the-pentagon-cybe) program.

By providing clear steps for reporting security vulnerabilities and transparent communication about remediation steps, we can work to build additional trust in our users.

Expand Down

0 comments on commit 44f048f

Please sign in to comment.