If you are in information security, and you say things like “the user is the last line of defense...” you’re in serious, long term trouble. It should not be the case that your users are your last line of defense. Discuss.
43
32
13
102
Startup idea: hire users that really ARE your last line of defense. Oh wait, that’s big bounty, never mind.

Dec 28, 2017 · 2:59 PM UTC

2
1
2
Bug bounties in theory help you find valid and valuable vulnerabilities. You still have to do a LOT of work to triage them and etc. And those are almost universally server-side, not client-side, where the... users are.
1
3