Bug bounties only work if the _right_ person is looking at your code. Those few qualified people are only just now looking at Zoom after all its recent attention. https://blog.trailofbits.com/2019/01/14/on-bounties-and-boffins/ …https://twitter.com/pwnsdx/status/1245137900477517831 …
-
Show this thread
-
I've had a few non-security / healthcare friends poke me to ask if using Zoom was still safe, and that their companies are advising them to switch to Google Meet. I honestly didn't expect this news to escape our echo chamber so quickly.
1 reply 0 retweets 8 likesShow this thread
Great summary of exactly the issue with bug bounties. "Many eyes" is a myth. You need the right set of eyes, and there are just very few of them. https://twitter.com/toholdaquill/status/1245717760832868352 …pic.twitter.com/HIhzKj5d9I
7:55 AM - 2 Apr 2020
0 replies
4 retweets
15 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.