Preskoči na sadržaj
Korištenjem servisa na Twitteru pristajete na korištenje kolačića. Twitter i partneri rade globalno te koriste kolačiće za analize, personalizaciju i oglase.

Za najbolje sučelje na Twitteru koristite Microsoft Edge ili instalirajte aplikaciju Twitter iz trgovine Microsoft Store.

  • Naslovnica Naslovnica Naslovnica, trenutna stranica.
  • O Twitteru

Spremljena pretraživanja

  • obriši
  • U ovom razgovoru
    Ovjeren akauntZaštićeni tweetovi @
Predloženi korisnici
  • Ovjeren akauntZaštićeni tweetovi @
  • Ovjeren akauntZaštićeni tweetovi @
  • Jezik: Hrvatski
    • Bahasa Indonesia
    • Bahasa Melayu
    • Català
    • Čeština
    • Dansk
    • Deutsch
    • English
    • English UK
    • Español
    • Filipino
    • Français
    • Italiano
    • Magyar
    • Nederlands
    • Norsk
    • Polski
    • Português
    • Română
    • Slovenčina
    • Suomi
    • Svenska
    • Tiếng Việt
    • Türkçe
    • Български език
    • Русский
    • Српски
    • Українська мова
    • Ελληνικά
    • עִבְרִית
    • العربية
    • فارسی
    • मराठी
    • हिन्दी
    • বাংলা
    • ગુજરાતી
    • தமிழ்
    • ಕನ್ನಡ
    • ภาษาไทย
    • 한국어
    • 日本語
    • 简体中文
    • 繁體中文
  • Imate račun? Prijava
    Imate račun?
    · Zaboravili ste lozinku?

    Novi ste na Twitteru?
    Registrirajte se
Profil korisnika/ce k8em0
Katie Moussouris
Katie Moussouris
Katie Moussouris
Ovjeren akaunt
@k8em0

Tweets

Katie MoussourisOvjeren akaunt

@k8em0

Founder/CEO @LutaSecurity . Bug bounty & vuln disclosure 👸🏽. Hacker. MIT Sloan & Harvard Belfer visiting scholar. @NewAmCyber & @MasonNatSec Fellow. She/her.

only Christoffel can tell.
lutasecurity.com
Vrijeme pridruživanja: srpanj 2008.

Tweets

  • © 2020 Twitter
  • O Twitteru
  • Centar za pomoć
  • Uvjeti
  • Pravila o privatnosti
  • Imprint
  • Kolačići
  • Informacije o oglasima
Odbaci
Prethodni
Sljedeće

Idite na profil osobe

Spremljena pretraživanja

  • obriši
  • U ovom razgovoru
    Ovjeren akauntZaštićeni tweetovi @
Predloženi korisnici
  • Ovjeren akauntZaštićeni tweetovi @
  • Ovjeren akauntZaštićeni tweetovi @

Odjava

Blokiraj

  • Objavi Tweet s lokacijom

    U tweetove putem weba ili aplikacija drugih proizvođača možete dodati podatke o lokaciji, kao što su grad ili točna lokacija. Povijest lokacija tweetova uvijek možete izbrisati. Saznajte više

    Vaši popisi

    Izradi novi popis


    Manje od 100 znakova, neobavezno

    Privatnost

    Kopiraj vezu u tweet

    Ugradi ovaj Tweet

    Embed this Video

    Dodajte ovaj Tweet na svoje web-mjesto kopiranjem koda u nastavku. Saznajte više

    Dodajte ovaj videozapis na svoje web-mjesto kopiranjem koda u nastavku. Saznajte više

    Hm, došlo je do problema prilikom povezivanja s poslužiteljem.

    Integracijom Twitterova sadržaja u svoje web-mjesto ili aplikaciju prihvaćate Twitterov Ugovor za programere i Pravila za programere.

    Pregled

    Razlog prikaza oglasa

    Prijavi se na Twitter

    · Zaboravili ste lozinku?
    Nemate račun? Registrirajte se »

    Prijavite se na Twitter

    Niste na Twitteru? Registrirajte se, uključite se u stvari koje vas zanimaju, i dobivajte promjene čim se dogode.

    Registrirajte se
    Imate račun? Prijava »

    Dvosmjerni (slanje i primanje) kratki kodovi:

    Država Kod Samo za korisnike
    Sjedinjene Američke Države 40404 (bilo koje)
    Kanada 21212 (bilo koje)
    Ujedinjeno Kraljevstvo 86444 Vodafone, Orange, 3, O2
    Brazil 40404 Nextel, TIM
    Haiti 40404 Digicel, Voila
    Irska 51210 Vodafone, O2
    Indija 53000 Bharti Airtel, Videocon, Reliance
    Indonezija 89887 AXIS, 3, Telkomsel, Indosat, XL Axiata
    Italija 4880804 Wind
    3424486444 Vodafone
    » Pogledajte SMS kratke šifre za druge zemlje

    Potvrda

     

    Dobro došli kući!

    Vremenska crta mjesto je na kojem ćete provesti najviše vremena i bez odgode dobivati novosti o svemu što vam je važno.

    Tweetovi vam ne valjaju?

    Prijeđite pokazivačem preko slike profila pa kliknite gumb Pratim da biste prestali pratiti neki račun.

    Kažite mnogo uz malo riječi

    Kada vidite Tweet koji volite, dodirnite srce – to osobi koja ga je napisala daje do znanja da vam se sviđa.

    Proširite glas

    Najbolji je način da podijelite nečiji Tweet s osobama koje vas prate prosljeđivanje. Dodirnite ikonu da biste smjesta poslali.

    Pridruži se razgovoru

    Pomoću odgovora dodajte sve što mislite o nekom tweetu. Pronađite temu koja vam je važna i uključite se.

    Saznajte najnovije vijesti

    Bez odgode pogledajte o čemu ljudi razgovaraju.

    Pratite više onoga što vam se sviđa

    Pratite više računa da biste dobivali novosti o temama do kojih vam je stalo.

    Saznajte što se događa

    Bez odgode pogledajte najnovije razgovore o bilo kojoj temi.

    Ne propustite nijedan aktualni događaj

    Bez odgode pratite kako se razvijaju događaji koje pratite.

    Katie Moussouris‏Ovjeren akaunt @k8em0 6. sij
    • Prijavi Tweet

    A look back & forward for bug bounties over the past decade, a thread. History is important for newcomers & established folks alike. Outcomes have been both positive & negative. Some fears of the largest tech companies have come true & worse. Huge opportunities & room to improve!pic.twitter.com/51lAhAPSpN

    07:17 - 6. sij 2020.
    • 70 proslijeđenih tweetova
    • 143 oznake „sviđa mi se”
    • sergey brrr Royce Williams Lina Inverse Rob Crawford olymppa KernelPanic José A. Hex Martinez 👨🏻‍💻🐧💀 Alan Watson Parisa Tabriz
    6 replies 70 proslijeđenih tweetova 143 korisnika označavaju da im se sviđa
      1. Novi razgovor
      2. Katie Moussouris‏Ovjeren akaunt @k8em0 6. sij
        • Prijavi Tweet

        Since this is just focused on the last decade, we’ll skip the Netscape bounty of 1995, summarizing that the price was steady at $500 for 15 years, & go straight to Google’s launch of their first bug bounty against Chromium. $1337 was offered for bugs. Later that year, $3133.7 .pic.twitter.com/WjrM9BjrJH

        3 proslijeđena tweeta 10 korisnika označava da im se sviđa
        Prikaži ovu nit
      3. Katie Moussouris‏Ovjeren akaunt @k8em0 6. sij
        • Prijavi Tweet

        That got some attention. Mozilla who continued the Netscape bug bounty, now against Firefox, raised their bounty to $3000. Why, if Netscape & then Mozilla had been doing this steadily for 15 years, was Google’s entry into paying for bugs a disruptive big deal? 2 reasons.pic.twitter.com/slHK0L29sZ

        1 reply 2 proslijeđena tweeta 4 korisnika označavaju da im se sviđa
        Prikaži ovu nit
      4. Katie Moussouris‏Ovjeren akaunt @k8em0 6. sij
        • Prijavi Tweet

        Prices going up from a previous high water mark was an obvious disruption - but not to offense market players, even though the false narrative was already starting back then that you needed to “compete” with the offense market for bugs if you made software Offense market be likepic.twitter.com/k5cRrOwrtA

        1 reply 1 proslijeđeni tweet 5 korisnika označava da im se sviđa
        Prikaži ovu nit
      5. Katie Moussouris‏Ovjeren akaunt @k8em0 6. sij
        • Prijavi Tweet

        The other disruption was Chrome itself. It was a brand new code base without big enterprise market share in 2010, & an update model that pushed silent patches. Internet Explorer had about 60% market share, Mozilla had about half that, & Chrome was only around 9% of the browsers.pic.twitter.com/yxMLOiwOwX

        1 reply 1 proslijeđeni tweet 2 korisnika označavaju da im se sviđa
        Prikaži ovu nit
      6. Katie Moussouris‏Ovjeren akaunt @k8em0 6. sij
        • Prijavi Tweet

        This was significant in it allowed Google much bolder moves in bug hunting & publicity from putting up cash. I was at Microsoft at the time & an exec had been quoted just 2 years prior saying that as long as he was there, MS would never pay for bugs. He’s still there, btw. 🤡pic.twitter.com/02Rdo2RZCB

        2 proslijeđena tweeta 20 korisnika označava da im se sviđa
        Prikaži ovu nit
      7. Katie Moussouris‏Ovjeren akaunt @k8em0 6. sij
        • Prijavi Tweet

        I was about to take a job at Adobe but my managers convinced me to stay. Promotion? No. Raise? Nah. I stayed because they asked me to work on how to possibly do bug bounties at the biggest software company in the world. The one that receives the most bug reports of anyone, stillpic.twitter.com/vVf0ZAM2SA

        1 reply 2 proslijeđena tweeta 17 korisnika označava da im se sviđa
        Prikaži ovu nit
      8. Katie Moussouris‏Ovjeren akaunt @k8em0 6. sij
        • Prijavi Tweet

        So I embarked on that journey starting w MS bug & labor cost data. Number crunching to estimate bounty budget, labor cost increases, & help decide initial scope. The perfectly good 1st draft bug bounty would have checked a few boxes. Would’ve been biggest & covered more products.pic.twitter.com/jbgVsBSdR2

        1 reply 1 proslijeđeni tweet 3 korisnika označavaju da im se sviđa
        Prikaži ovu nit
      9. Katie Moussouris‏Ovjeren akaunt @k8em0 6. sij
        • Prijavi Tweet

        At the time, it would have cost less in $5000 bug bounties for all bugs rated “Critical or Important” for Windows, IE, & Office for the latest versions plus 2 versions going back, than a single emergency patch process (called a SSIRP). Avg SSIRP was ~$6M. $1.8M was all I neededpic.twitter.com/X83IXHwXgw

        1 proslijeđeni tweet 12 korisnika označava da im se sviđa
        Prikaži ovu nit
      10. Katie Moussouris‏Ovjeren akaunt @k8em0 6. sij
        • Prijavi Tweet

        So why didn’t they pull the trigger in 2010? Even though we knew we wouldn’t prevent all SSIRPs (Software Security Incident Response Protocol), this seemed like an easy win, right? Because it wasn’t about money. It was about competing w a growing threat in the marketplace: Chromepic.twitter.com/0Wlm848wTb

        1 proslijeđeni tweet 10 korisnika označava da im se sviđa
        Prikaži ovu nit
      11. Katie Moussouris‏Ovjeren akaunt @k8em0 6. sij
        • Prijavi Tweet

        Only I didn’t know that at the time. I also didn’t yet fully comprehend the massive politics that money couldn’t address fully: Who would pay for the increase in triage volume? MS Response already had high triage turnover MS already received >200,000 non-spam email messages/yearpic.twitter.com/BuJmaflIgG

        1 reply 2 proslijeđena tweeta 12 korisnika označava da im se sviđa
        Prikaži ovu nit
      12. Katie Moussouris‏Ovjeren akaunt @k8em0 6. sij
        • Prijavi Tweet

        I could keep this thread going longer w the Harvard biz professor-written economics papers, or MSR game theory papers that I commissioned over those next 2 years. While they played a part in shaping the bounties, none of them got MS to pay for what it was already getting for freepic.twitter.com/y2PlEQqlGs

        1 reply 2 proslijeđena tweeta 9 korisnika označava da im se sviđa
        Prikaži ovu nit
      13. Katie Moussouris‏Ovjeren akaunt @k8em0 6. sij
        • Prijavi Tweet

        So what changed in 2013 that allowed me to finally announce the 1st MS bug bounties? It happened back in 2011, after we had announced the largest defensive prize ever: $250,000 in prizes for new platform-wide technical exploit mitigations. What happened? Chrome overtook IE.pic.twitter.com/HTOTxUbBcT

        1 reply 2 proslijeđena tweeta 11 korisnika označava da im se sviđa
        Prikaži ovu nit
      14. Katie Moussouris‏Ovjeren akaunt @k8em0 6. sij
        • Prijavi Tweet

        We’d committed to run the BlueHat Prize for defense 1st tho. (Google totes hired one of the winners, lol, good one guys! 😂) But the bounty beast was still on my back to solve, so with my 12 slide deck, 1000 meetings later, I finally got a meeting w the head of IE April 4 2013pic.twitter.com/ArvHMquY3h

        1 reply 1 proslijeđeni tweet 10 korisnika označava da im se sviđa
        Prikaži ovu nit
      15. Katie Moussouris‏Ovjeren akaunt @k8em0 6. sij
        • Prijavi Tweet

        Katie Moussouris je proslijedio/a tweet korisnika/ceKatie Moussouris

        The plan was calculated for a crawl-walk-run approach in scope, with expansions planned in budget, staff, & products included projected over the next 3 years. When we got to slide 2, he waved his hand & said: I’m going to make this easy on you. How much? It was the left slidehttps://twitter.com/k8em0/status/1008393048047226880 …

        Katie Moussouris je dodan/na,

        Katie MoussourisOvjeren akaunt @k8em0
        Odgovor korisnicima @k8em0 @yaworsk @fsmontenegro
        Here's a slide w some of that data. This convinced IE to fund their bug bounty program at Microsoft. We were already getting tons of bugs for free. Over 200k reports each year. But before bounties, bug hunters hoarded them until after beta was over, or until pwn2own. pic.twitter.com/HNVNE5pTsh
        1 reply 1 proslijeđeni tweet 14 korisnika označava da im se sviđa
        Prikaži ovu nit
      16. Katie Moussouris‏Ovjeren akaunt @k8em0 6. sij
        • Prijavi Tweet

        Not to recapitulate the thread I just quoted above, the move was strategic traffic shaping to get bugs early in the beta, instead of after beta was closed, which was generally bad for anyone. It was deadly for a browser in market share decline against fast-patching rival Chrome.pic.twitter.com/XJHjJqIBjy

        1 reply 1 proslijeđeni tweet 12 korisnika označava da im se sviđa
        Prikaži ovu nit
      17. Katie Moussouris‏Ovjeren akaunt @k8em0 6. sij
        • Prijavi Tweet

        Suddenly, we had money committed from the 1st targeted product team, & we’d built up additional internal staff capacity planning for increased labor costs in MSRC. IE set timing: We’d announce 1 week prior the IE11 beta release. June 19, 2013. June 5, this guy made headlines.pic.twitter.com/RTqSEpYRxm

        1 reply 1 proslijeđeni tweet 11 korisnika označava da im se sviđa
        Prikaži ovu nit
      18. Katie Moussouris‏Ovjeren akaunt @k8em0 6. sij
        • Prijavi Tweet

        Everyone in MS security was on strict lockdown, total media blackout, no spokespeople talking to reporters, even on unrelated security news we wanted to share. But the bounties couldn’t wait. So IE comms overruled TWC comms & thus, we were STILL ON to announce the bounties.pic.twitter.com/qugMIu68rL

        1 proslijeđeni tweet 11 korisnika označava da im se sviđa
        Prikaži ovu nit
      19. Katie Moussouris‏Ovjeren akaunt @k8em0 6. sij
        • Prijavi Tweet

        Thought I would do this in one history thread, but I’m tired, this is long already, & we haven’t even gotten to Hack the Pentagon yet. I’ll let you all vote on the next installment & pause for now. Next thread chapter should go through which branch of bug bounty history?

        2 proslijeđena tweeta 11 korisnika označava da im se sviđa
        Prikaži ovu nit
      20. Katie Moussouris‏Ovjeren akaunt @k8em0 6. sij
        • Prijavi Tweet

        Click on the above link to expand the tweet, see the poll & vote. I’m not doing write-ins for this. :) I have a company to run, & though The bounty weeds are lovely, dark & deep, I have promises to keep, And miles to go before I sleep, & miles to go before I sleep.

        1 proslijeđeni tweet 18 korisnika označava da im se sviđa
        Prikaži ovu nit
      21. Katie Moussouris‏Ovjeren akaunt @k8em0 6. sij
        • Prijavi Tweet

        Ok I am going to leave the Twitter poll open for a day, but I just have to laugh at the early results that have people’s interest in the rise of bug bounty platforms on par with their curiosity about my homegrown lettuce 🥬😂🤣 Maybe their investors should look into hydroponics.pic.twitter.com/vGbXFqkQIM

        1 reply 2 proslijeđena tweeta 12 korisnika označava da im se sviđa
        Prikaži ovu nit
      22. Katie Moussouris‏Ovjeren akaunt @k8em0 7. sij
        • Prijavi Tweet

        9 hours left to vote on the next installment of This Old Decade - Bug Bounty edition. I’m still kind of dying 🤣 over here that my aeropod lettuce 🥬 garden is still steadily dusting Rise of Bounty Platforms. The lettuce may well beat Regulatory Nincompoopery at this rate. 🤷🏽‍♀️pic.twitter.com/frZK8uixel

        0 proslijeđenih tweetova 6 korisnika označava da im se sviđa
        Prikaži ovu nit
      23. Katie Moussouris‏Ovjeren akaunt @k8em0 8. sij
        • Prijavi Tweet

        Poll results are in! A clear majority want to know what happened next chronologically, followed by regulatory nincompoopery, then a lettuce garden update, then the rise of bounty platforms.🤷🏽‍♀️ Where were we... Right about to announce the first MS bounties in Bangkok at midnightpic.twitter.com/nxxEpZY3cE

        1 reply 1 proslijeđeni tweet 6 korisnika označava da im se sviđa
        Prikaži ovu nit
      24. Katie Moussouris‏Ovjeren akaunt @k8em0 8. sij
        • Prijavi Tweet

        Why Bangkok at midnight? April to June (from getting the green light from IE to the announcement) wasn’t long, & I was already committed to speaking at the FIRST conference about upcoming ISO standards governing Vuln disclosure & handling processes. So we’d have to announce therepic.twitter.com/JBhIIRzCJt

        1 reply 0 proslijeđenih tweetova 4 korisnika označavaju da im se sviđa
        Prikaži ovu nit
      25. Katie Moussouris‏Ovjeren akaunt @k8em0 8. sij
        • Prijavi Tweet

        I thought it polite to warn the FIRST board that I was about to do this radical change from my proposed ISO talk scheduled for the morning, so I briefed the chair of FIRST at the time, my friend Steve Adegbite. He & I shared it w the rest of the board, some of whom WERE FURIOUS.pic.twitter.com/5WtdooC8YU

        1 reply 0 proslijeđenih tweetova 5 korisnika označava da im se sviđa
        Prikaži ovu nit
      26. Katie Moussouris‏Ovjeren akaunt @k8em0 8. sij
        • Prijavi Tweet

        The FIRST board contains employees of the largest companies. One of them said “How dare you break ranks & start paying?” I responded by saying I’d be happy to help him w talking points about why his company wasn’t doing bug bounties. I don’t think he heard me through the rage.pic.twitter.com/P4rxicMZXp

        1 reply 0 proslijeđenih tweetova 5 korisnika označava da im se sviđa
        Prikaži ovu nit
      27. Katie Moussouris‏Ovjeren akaunt @k8em0 8. sij
        • Prijavi Tweet

        Here’s a good time to talk about fear. He wasn’t wrong to be afraid of what this meant for other companies of Microsoft’s size & age. MS had over 800 supported products, services, & even hardware, & tons of legacy code & hard to fix dependencies - & that was just current versionspic.twitter.com/jztXolggpD

        1 reply 0 proslijeđenih tweetova 4 korisnika označavaju da im se sviđa
        Prikaži ovu nit
      28. Katie Moussouris‏Ovjeren akaunt @k8em0 8. sij
        • Prijavi Tweet

        Remember how Google got to start their bug bounty on a single new product w no legacy code & not enough browser market share to make it very risky for them then? Yeah, completely different set of problems for older orgs. So I designed the IE beta bounty & mitigation bypass bountypic.twitter.com/4n6I8hQeRF

        1 reply 1 proslijeđeni tweet 7 korisnika označava da im se sviđa
        Prikaži ovu nit
      29. Katie Moussouris‏Ovjeren akaunt @k8em0 8. sij
        • Prijavi Tweet

        We set the mitigation bypass bounty at $100,000, the same top prize offered the same year at the @Pwn2Own_Contest . One of the fears expressed by MS internally & this FIRST board member seething at me hours before we announced, was prices increasing past the point of feasibility.pic.twitter.com/bD6mrQHDxJ

        1 reply 0 proslijeđenih tweetova 4 korisnika označavaju da im se sviđa
        Prikaži ovu nit
      30. Katie Moussouris‏Ovjeren akaunt @k8em0 8. sij
        • Prijavi Tweet

        We’ll get to the current million dollar bounties later. Sticking to chronological order, now I had to wait for 10 AM Redmond time, when my blogs & the official page with the bounty rules would go live. I was in Bangkok. Who did I know in Bangkok? My friend @thegrugq , that’s who!pic.twitter.com/ZI7WczFtqB

        4 proslijeđena tweeta 12 korisnika označava da im se sviđa
        Prikaži ovu nit
      31. Katie Moussouris‏Ovjeren akaunt @k8em0 8. sij
        • Prijavi Tweet

        My friends @l33tdawg & @BelindaChoong flew from Malaysia to check out FIRST, so after drinks w @thegrugq , @ChrisJohnRiley , & @mckeay , we headed back to my room to wait for the crack of midnight. I called @dakami @0xcharlie @dinodaizovi & a couple others right before announcingpic.twitter.com/hhuuutK1qK

        0 proslijeđenih tweetova 8 korisnika označava da im se sviđa
        Prikaži ovu nit
      32. Još 36 drugih odgovora

    Čini se da učitavanje traje već neko vrijeme.

    Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.

      Sponzorirani tweet

      false

      • © 2020 Twitter
      • O Twitteru
      • Centar za pomoć
      • Uvjeti
      • Pravila o privatnosti
      • Imprint
      • Kolačići
      • Informacije o oglasima