72,000 Steps
Everyone at Bugcrowd is a big fan of Mr. Robot. Spotted @ItsRamiMalek at #rsac2016 pic.twitter.com/QT5MkvvSmp
— bugcrowd (@Bugcrowd) March 1, 2016
It’s cool to know that Rami is into this incredible community, and even though he’s not a “real hacker” he has clearly dug in and done a ton of research prior to filming. We’re big Mr. Robot fans at the Bugcrowd HQ and have weekly screenings. Needless to say, we’re looking forward to next season.
25,000 Crowd Members
Today we hit the 25,000 Researcher milestone! Sincere thanks to our amazing researcher community ❗ pic.twitter.com/vQW6gDJEsW
— bugcrowd (@Bugcrowd) March 2, 2016
The growth of our crowd is a continual source of excitement and fascination at Bugcrowd, as hackers from all walks of life and from all around the world join our ranks. Our community is made up of 25,000 talented and passionate people from diverse backgrounds, who have all come together to make the Internet’s products and services more secure. Without these researchers we wouldn’t be where we are today, and you can count on Bugcrowd to continue to invest in our researcher community.
10,000 Twitter Followers
We passed 10,000 Twitter followers at the end of the week, and while that’s a somewhat trivial number compared to our 25,000-strong crowd, this body of active and engaging folks have been instrumental in curating and bolstering dialogue around the vulnerability disclosure and bug bounty space, and we learn from them each and every day. Thanks to all of our followers!
300+ Talks, sessions and briefings
- On Tuesday the “2016 State of Vulnerability Exploits” talk by Amol Sarwate, Director of Vulnerability Research at Qualys gave us insight on how to “build a prioritized defense strategy in 2016” See the slides here.
- Our good friend Michael Murray gave a great talk “Product Security at Internet Scale” outlining how organizations need to build security cultures to fully recognize true product security.
- In the wee-small hours of Wednesday Julian Cohen gave an amazing talk on Intelligent Application Security, offering insights into how traditional penetration testing is not the be-all and end-all of application security, and often leaves companies vulnerable to highly likely attacks. He brought economic incentive into the ring, which is a subject near and dear to our hearts… Because pen testers act as hobbyists while attackers act as resource constrained businesses, the motivations and methodologies are misaligned.
- On Wednesday U.S. Secretary of Defense Ashton Carter was part of “A Conversation on Collaboration Between Silicon Valley and the Department of Defense“, where shared some interesting insights… And dropped an incredible announcement that we’ll share more about below (Spoiler: The DoD is starting a bug bounty program).
- Of course, no conference is complete without the Charle/Chris show and they certainly delivered, with an entertaining low-down on on the latest findings from their car hacking research, as well as some practical tips for newcomers. As the security industry realizes that cars are basically 2-ton mobile phones, their ‘Intro to Car Hacking’ talk was a must see.
Wow! Awesome crowd in the #RSAC Sandbox for @0xcharlie & @nudehaberdasher for their intro to car #hacking preso pic.twitter.com/Ej9FyWX7JD
— RSA Conference (@RSAConference) March 2, 2016
- When Good Devices Go Bad: Live Hacking in the IoT Sandbox discussed some best practices for IoT vendors and the consumer threats that come with connected devices, hacked a smart lock and zapped a fake dog on stage to prove the point, and offered some good steps for a plan of attack.
60 awesome bc employees
- Our marketing team worked tirelessly to ensure all logistics and communications were handled with care.
- Our sales and researcher ops teams were instrumental in generating buzz, getting feedback, and speaking with folks from every corner of the industry – both hacker and vendor.
- Our engineering team used this opportunity to generate excitement among top recruits and to chat with other SaaS platform engineers and owners.
- And of course, our extended family… our customers, researchers, friends and advocates in the industry… thank you for your tireless support and devotion.
22 press mentions
- Forbes,
- The Register,
- eWeek,
- FedScoop,
- Infosecurity Magazine,
- NYSE Post,
- and more
20 years
Congrats to Art Coviello for receiving the #RSAC Lifetime Achievement Award! Glad you’re part of the Bugcrowd family pic.twitter.com/a1pFNEzvxZ
— bugcrowd (@Bugcrowd) March 1, 2016
5 co-sponsors
2 trending news topics
With all the happy hours, press meet-ups, Hallway con at large and interviews galore, two major trending news topics jumped out at us throughout the week…
ok ok ok, one more… #cyberpathogens pic.twitter.com/253RAfYmTB
— caseyjohnellis (@caseyjohnellis) March 4, 2016