@"Mr William"
Lots of "should" and "shouldn't" opinions there. I'm just relaying what you really get when you deal with these programs.
Nothing exists in a vacuum. If you don't like what you're getting, stop following a program that works in counterproductive ways (or, to phrase it ironically/paradoxically, fix the bugs in your bug bounty system). Call it mere opinion if you wish, but I'm not sure how trying to dismiss advice like mine is going to help you. I mean, I'd like to think Bruce is highlighting this article because he'd like to see a better outcome than your sentiment of resignation.
Presumptuous and it sounds like your just fighting your own strawman... the whole program costs less then 1 full time infosec person so its a "if it keeps the internal staff honest than why not" situation.
There's no need for me to construct a straw man when you continually post evidence that your organization is doing things wrong. Rather than using the system to provide better security, you acknowledge that it is really about getting cheaper "security". The need to keep your security employees "honest" is an acknowledgement that HR has not done its job to find professionals to do the work. Nor does it help that you keep using the term "researcher" for the spec work mercenaries that you maintain a contestable relationship with.
The bottom line is that there are professional approaches and unprofessional ones. Even if you have a security apparatus that forwards a lot of professional actions, there is still a responsibility to eliminate all the elements that push for these unprofessional ones. That may mean getting new security staff, replacing security (or other) management, or raising the whole HR department if they can't competently locate enough professional employees at any level. See the ruling in Chain v. Weakest Link.
fb2b735ac4aae36637034d9cf028f18b91f9b346fa2764959ae7317e3d5ae368