Ask HN: Do I need a bug bounty program? Feeling a bit threatened by HackerOne
I understand how the sales process works, but I'm kind of starting to feel after the second cold email that this is a bit mafia-like. I'm basically being told that my kneecaps are going to be bashed in by hackers if I don't respond to this sales call, at least that's how I'm reading this communique.
I was thinking a good way to respond would be to at least put something about responsible disclosure on our "Contact Us" page, and that we'd pay a bounty if someone finds something out of the ordinary. A security professional told me allowing responsible disclosure is the first step. We're a very small company though, I'm the sole developer. I know security is important, and I try to follow best practices - but has anyone else gotten these emails and felt a bit threatened?
I don't meant to insinuate that Hacker One is going to be doing hacking themselves, I'm not a conspiracy theorist. I'm just wondering how people are reacting to getting emails like this?
Thanks for any perspective.