Sunday, June 15, 2025
India Watch - A Digital Media
  • Home
  • IndiaWatching
    • India Unplugged
    • Maps of India
    • Strategy & Policy
  • Makers for India
    • Gallery & Expo
  • More
    • About Us
    • Contact Us
No Result
View All Result
India Watch - A Digital Media
  • Home
  • IndiaWatching
    • India Unplugged
    • Maps of India
    • Strategy & Policy
  • Makers for India
    • Gallery & Expo
  • More
    • About Us
    • Contact Us
No Result
View All Result
India Watch - A Digital Media
No Result
View All Result
Home India Unplugged

Voices of the Indian Bug Bounty Researchers

Dinesh Bareja by Dinesh Bareja
06/12/2016
in India Unplugged
0

20161206-indiawatch-bug-bountyIndian Bug Bounty (BB) researchers are highly respected professionals by foreign corporations and make good money. Hundreds of these young folks have high places in the Halls of Fame (HoF) set up by the whos-who of global corporations like Microsoft, Google, Facebook, Twitter etc. They are making money, getting recognition and gifts from all over the world.

And they are paying taxes on their income!

Unfortunately, hardly any Indian organization (government or private) is engaging well with any BB professionals. And the few companies which have BB programs pay out small change (it may be better not to pay any money and just have a HoF).

In any case, since Indian organizations think that these BB guys cannot be trusted (or whatever), I decided to get these guys to share their point of view about the Government and Corporations. Read on for some free advise and a lot of common sense guidance!

BB Professional # 01

This is the first professional to respond and as more responses are received their voices will be added to this blog. The response has not been edited and is reproduced verbatim and the individual is not identified for obvious reasons.

Q 1. What is your biggest hassle with Indian government

  • I’ve worked with a reputed police force IGP/IPS in India and I found them to be extremely slow. We required rapid decisions. But the issue was, all decisions were taken via a committee and not members were present all the time. As a result, we had to wait unbearably long to get approvals for simple things. Lesson we learned is, government works at the speed of tortoise and if you are dealing with them – start early and expect a lengthy process.
    So, biggest hassle with government is slow response – if you’re lucky enough to even get one.

Q 2. What’s your biggest hassle with Indian companies

  • For business purposes, I contacted lot of companies in both India and China. This is specific to electronic manufacturing industry. And major difference I found was lack of proper communication. When I was working on badges for a conference, we had to outsource few processes to make it extra-ordinary. However, out of all manufacturing people I contacted, only 1 responded. Mind you, I contacted like 50 of them. And I even went onto call them and say “I’ve sent you email. Please check it and let me know if you …. let me know if you’ll be able to do it. Not a single response.
  • Compare that to China, the moment I landed on Alibaba, I found Chinese extremely eager to contact me and lead the project. This was the primary reason I got into electronic manufacturing.
    For conference founders, manufacturing badges was big pain – which we are trying to solve with our innovation and hard work.

Q3. Are Indian organizations having good security?

  • NO.
  • A big No. I’ve often found that companies underestimate importance of security – not just in India but worldwide.
    And they don’t understand the importance until they’re victim of attack.
    I’ve heard first hand stories of how management guys totally discarded the idea of security – calling it money making scheme and nothing serious.
    Hence, I think India has long way to go to be secured.
    Silver lining is we’ve lot of hacking talent. Indian bug bounty hunters are topping the list of Facebook and Google – and I am sure that if Indian companies allow similar bug disclosure policies, things will start to change.

====== updated 1430 hrs Dec 06, 2016 ======

BB Professional # 02

This is the second professional to respond and as more responses are received their voices will be added to this blog. The response has not been edited and is reproduced verbatim (with typos 🙂 )and the individual is not identified for obvious reasons.

Q 1. What is your biggest hassle with Indian Companies

  • As u all know that Netherlands is running private bug bounty program that if you find any bug in .nl website then they will pay you bounty or reward for that but indian government doesn’t have any this kind of policies.

Q3. Are Indian organizations having good security?

  • no, indian sites doesn’t have that good secure sites because their firewalls are not enough updated! Mostly sites are hosed in indian servers which are not secure enough and top of that they dont do wapt for their site.

=================================

Tags: bug bountybug bounty researcherscommon senseCyber SecurityIndia bug bountyinformation security
Previous Post

Be Warned - The Future of India is in Peril

Next Post

Makers for India - BARC

Dinesh Bareja

Dinesh Bareja

Cyber Security practitioner and evangelist working in cyber security in national and enterprise application. Contributor to national policy, awareness and development of capacity / capability. Keeps a critical eye on the past, present and future in the infosec domain, and firm believer in common sense. Uses practical thinking to demolish purveyors of cyber hype and snake-oil.

Next Post

Makers for India - BARC

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

9 + nine =

  • Trending
  • Comments
  • Latest

Skeletons in my banks and national system

17/04/2018

Corporate Governance & Cyber Security Responsibility

18/11/2016

Chai pe Charcha – Delhi 11 June 2017

14/06/2017

Govt & Cops twiddle fingers waiting for the nation to burn…

26/08/2017
National Cyber Security Policy 2020 .. in anticipation

National Cyber Security Policy 2020 .. in anticipation

7

Cyber Swatchhta Kendra – A Good Start

6

Demonetisation – Cashless Economy – Urgent Need For Data Localisation

5

Why Are We A Strategically Deficient Nation ?

5
Time to relook at Critical Information Infrastructure

Time to relook at Critical Information Infrastructure

20/09/2020
What the Government does… secure messaging

What the Government does… secure messaging

23/01/2020
They ran, we shot… and u better believe us!

They ran, we shot… and u better believe us!

06/12/2019
National Cyber Security Policy 2020 .. in anticipation

National Cyber Security Policy 2020 .. in anticipation

31/10/2019

Recent News

Time to relook at Critical Information Infrastructure

Time to relook at Critical Information Infrastructure

20/09/2020
What the Government does… secure messaging

What the Government does… secure messaging

23/01/2020
They ran, we shot… and u better believe us!

They ran, we shot… and u better believe us!

06/12/2019
National Cyber Security Policy 2020 .. in anticipation

National Cyber Security Policy 2020 .. in anticipation

31/10/2019
  • Home
  • About
  • Contact
  • Maps of India

© 2018 IndiaWatch - All Rights Reserved. Website Design: Jemistry Info Solutions

  • Home
  • IndiaWatching
    • India Unplugged
    • Maps of India
    • Strategy & Policy
  • Makers for India
    • Gallery & Expo
  • More
    • About Us
    • Contact Us

© 2018 IndiaWatch - All Rights Reserved. Website Design: Jemistry Info Solutions

Login to your account below

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.