<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Bugs Money</title>
	<atom:link href="http://krebsonsecurity.com/2011/12/bugs-money/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2011/12/bugs-money/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Wed, 19 Jun 2013 01:42:39 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Jango Fett</title>
		<link>http://krebsonsecurity.com/2011/12/bugs-money/comment-page-1/#comment-43592</link>
		<dc:creator>Jango Fett</dc:creator>
		<pubDate>Wed, 21 Dec 2011 02:11:13 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=12688#comment-43592</guid>
		<description><![CDATA[These &quot;bounties&quot; are just spec work moved to a different domain.  The scenario is the same as in the creative design world: many toil, few are paid, all are exploited.

Security researchers do have one bit of leverage that artists don&#039;t; they can sell the product of their labors to the black hats.  But they have dance carefully to avoid extortion or criminal accessory charges.  Still, in the end I think selling to the bad guys is the best way to increase the number of security pros actually hired as opposed to being merely exploited in these contests.]]></description>
		<content:encoded><![CDATA[<p>These &#8220;bounties&#8221; are just spec work moved to a different domain.  The scenario is the same as in the creative design world: many toil, few are paid, all are exploited.</p>
<p>Security researchers do have one bit of leverage that artists don&#8217;t; they can sell the product of their labors to the black hats.  But they have dance carefully to avoid extortion or criminal accessory charges.  Still, in the end I think selling to the bad guys is the best way to increase the number of security pros actually hired as opposed to being merely exploited in these contests.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JCitizen</title>
		<link>http://krebsonsecurity.com/2011/12/bugs-money/comment-page-1/#comment-43004</link>
		<dc:creator>JCitizen</dc:creator>
		<pubDate>Sun, 18 Dec 2011 06:34:42 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=12688#comment-43004</guid>
		<description><![CDATA[Great article Brian! It is so good to see people making a positive difference for once!]]></description>
		<content:encoded><![CDATA[<p>Great article Brian! It is so good to see people making a positive difference for once!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: F-3000</title>
		<link>http://krebsonsecurity.com/2011/12/bugs-money/comment-page-1/#comment-42392</link>
		<dc:creator>F-3000</dc:creator>
		<pubDate>Wed, 14 Dec 2011 13:47:38 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=12688#comment-42392</guid>
		<description><![CDATA[My usual comment for people who tell me that they don&#039;t have Facebook account is &quot;you have lost nothing&quot;.

What I find rather negative aspect, is that there&#039;s a lot of site specific forums, yet people use only facebook groups when/if one is created.

Why it is not good that the facebook group is more used than a site forum?
Firstly, Facebook is not safe media. As a mere example, a browser-addon meant to be a FB-game tool, may reveal basically anything that&#039;s written in a closed group, if the tool&#039;s written badly, or if it&#039;s purposely malicious. Less likely to happen when the game-site, and the forum are on different source.
Secondly, Facebook is not stable media. Those who are members of groups, and especially those who are admins of groups, remember too well about the group-renewal of Facebook, which happened short ago. A lot of groups went to &quot;archives&quot;, because the updating system did not even work for those who did not use english as FB language, until it was  too late. On occasion, groups, or even user-accounts, go missing or unaccessible without clear reason about what has happened.]]></description>
		<content:encoded><![CDATA[<p>My usual comment for people who tell me that they don&#8217;t have Facebook account is &#8220;you have lost nothing&#8221;.</p>
<p>What I find rather negative aspect, is that there&#8217;s a lot of site specific forums, yet people use only facebook groups when/if one is created.</p>
<p>Why it is not good that the facebook group is more used than a site forum?<br />
Firstly, Facebook is not safe media. As a mere example, a browser-addon meant to be a FB-game tool, may reveal basically anything that&#8217;s written in a closed group, if the tool&#8217;s written badly, or if it&#8217;s purposely malicious. Less likely to happen when the game-site, and the forum are on different source.<br />
Secondly, Facebook is not stable media. Those who are members of groups, and especially those who are admins of groups, remember too well about the group-renewal of Facebook, which happened short ago. A lot of groups went to &#8220;archives&#8221;, because the updating system did not even work for those who did not use english as FB language, until it was  too late. On occasion, groups, or even user-accounts, go missing or unaccessible without clear reason about what has happened.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: geeknik</title>
		<link>http://krebsonsecurity.com/2011/12/bugs-money/comment-page-1/#comment-42282</link>
		<dc:creator>geeknik</dc:creator>
		<pubDate>Tue, 13 Dec 2011 19:43:29 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=12688#comment-42282</guid>
		<description><![CDATA[I&#039;ve made some quick cash through Google and Mozilla&#039;s bug bounty programs, but I didn&#039;t know about Facebook, CCBill and Piwik. Time to get cracking, so to speak. ;)]]></description>
		<content:encoded><![CDATA[<p>I&#8217;ve made some quick cash through Google and Mozilla&#8217;s bug bounty programs, but I didn&#8217;t know about Facebook, CCBill and Piwik. Time to get cracking, so to speak. <img src='http://krebsonsecurity.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: helly</title>
		<link>http://krebsonsecurity.com/2011/12/bugs-money/comment-page-1/#comment-42258</link>
		<dc:creator>helly</dc:creator>
		<pubDate>Tue, 13 Dec 2011 15:26:07 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=12688#comment-42258</guid>
		<description><![CDATA[I was lucky enough to find a vuln in google search a few months back, I thought the hall of fame was a neat idea. I love this card idea, it continues to make it interesting for researchers to report vulnerabilities in ways a company desires. 

These programs I think are extremely beneficial, and it would be exciting to see more companies continue to emulate these models.]]></description>
		<content:encoded><![CDATA[<p>I was lucky enough to find a vuln in google search a few months back, I thought the hall of fame was a neat idea. I love this card idea, it continues to make it interesting for researchers to report vulnerabilities in ways a company desires. </p>
<p>These programs I think are extremely beneficial, and it would be exciting to see more companies continue to emulate these models.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jay Wocky</title>
		<link>http://krebsonsecurity.com/2011/12/bugs-money/comment-page-1/#comment-42256</link>
		<dc:creator>Jay Wocky</dc:creator>
		<pubDate>Tue, 13 Dec 2011 15:05:20 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=12688#comment-42256</guid>
		<description><![CDATA[I don&#039;t recall invoking ignorance to excuse my Facebook-o-phobia. Indeed, my avoidance of FB &lt;i&gt;et al. simili&lt;/i&gt; is based in considerable research and anecdotal evidence.

As for fear, well: I walk generally without fear. But I stay off of tight ropes with the same mindset that eschews social networking. Thus far, neither abstinence seems to have narrowed the universe for me. Rather, I reap the benefit of time to spend on better things.]]></description>
		<content:encoded><![CDATA[<p>I don&#8217;t recall invoking ignorance to excuse my Facebook-o-phobia. Indeed, my avoidance of FB <i>et al. simili</i> is based in considerable research and anecdotal evidence.</p>
<p>As for fear, well: I walk generally without fear. But I stay off of tight ropes with the same mindset that eschews social networking. Thus far, neither abstinence seems to have narrowed the universe for me. Rather, I reap the benefit of time to spend on better things.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: steve</title>
		<link>http://krebsonsecurity.com/2011/12/bugs-money/comment-page-1/#comment-42253</link>
		<dc:creator>steve</dc:creator>
		<pubDate>Tue, 13 Dec 2011 14:32:17 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=12688#comment-42253</guid>
		<description><![CDATA[@Datz - yes, go out into the cyber world, but NOT fearlessly.  Ask any hero - they felt the fear and did it anyway.  Fearless leads to foolish risk, not prudent behavior.]]></description>
		<content:encoded><![CDATA[<p>@Datz &#8211; yes, go out into the cyber world, but NOT fearlessly.  Ask any hero &#8211; they felt the fear and did it anyway.  Fearless leads to foolish risk, not prudent behavior.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BrianKrebs</title>
		<link>http://krebsonsecurity.com/2011/12/bugs-money/comment-page-1/#comment-42241</link>
		<dc:creator>BrianKrebs</dc:creator>
		<pubDate>Tue, 13 Dec 2011 13:19:33 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=12688#comment-42241</guid>
		<description><![CDATA[Thanks, Michal. Fixed that.]]></description>
		<content:encoded><![CDATA[<p>Thanks, Michal. Fixed that.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Datz</title>
		<link>http://krebsonsecurity.com/2011/12/bugs-money/comment-page-1/#comment-42230</link>
		<dc:creator>Datz</dc:creator>
		<pubDate>Tue, 13 Dec 2011 11:25:41 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=12688#comment-42230</guid>
		<description><![CDATA[Would you also stop walking because you fear you may fall down?  Ignorance is no excuse; arm yourself with the knowledge and go out fearlessly in this cyber world.]]></description>
		<content:encoded><![CDATA[<p>Would you also stop walking because you fear you may fall down?  Ignorance is no excuse; arm yourself with the knowledge and go out fearlessly in this cyber world.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michał</title>
		<link>http://krebsonsecurity.com/2011/12/bugs-money/comment-page-1/#comment-42229</link>
		<dc:creator>Michał</dc:creator>
		<pubDate>Tue, 13 Dec 2011 11:24:39 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=12688#comment-42229</guid>
		<description><![CDATA[There is a typo in the Niebezpiecznik&#039;s URL - you forgot http Brian, link doesn&#039;t work.
Glad to see Niebezpiecznik here, they are quite popular in Poland, educating in itsec.]]></description>
		<content:encoded><![CDATA[<p>There is a typo in the Niebezpiecznik&#8217;s URL &#8211; you forgot http Brian, link doesn&#8217;t work.<br />
Glad to see Niebezpiecznik here, they are quite popular in Poland, educating in itsec.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 5/18 queries in 0.006 seconds using memcached
Object Caching 382/390 objects using memcached

 Served from: krebsonsecurity.com @ 2013-06-18 21:46:52 by W3 Total Cache -->