Today @bugcrowd, we're expanding our product line to offer VDP's for free bugcrowd.com/blog/introduci…, marking the next evolution of our VDP product, following our removal of incentives some time back. This marks a change in the industry, providing a no cost entry point for customers to build up reporting portals, to support hackers in bringing vulnerabilities to them, in a fast, and effective manner. It also allows customers to build exposure to the value of the hacking community, and then pursue other offerings in the managed bug bounty space, or pen testing space, in a paid model, that incentivises findings and discovery, whilst VDP is intended to capture existing known findings. Also, hackers, we hear you, we love you and we know there's more to change around VDP's. This isn't our only change. We're aware of the need to change terms for them, and it's currently an active discussion, as well as better separating VDP from MBB which we've done by removing incentives, and having this offering not list in our program portals. If you've other feedback, we would love to hear it, and welcome it - my slack is always open and you can reach me on HIVE, Bug Bounty Forum, or here over DM
@codingo_ @infosec_au @Bugcrowd Had a skim of the post but it wasn’t immediately clear (or I failed to read..); but from a researcher perspective, are my submissions still tied to my account? And while I know there’s no points/etc; will they show up on my profile stats for that badges/etc type dopamine hit?
@_devalias @infosec_au @Bugcrowd Yes, and yes - but badges/incentive are not tied to VDP. Made aware today that some badges still are, and seeking to change that ASAP.