Edinburgh University Students' Association
Human Factors in Security-Sensitive User Research
Pages
51
Time to read
8 mins
Publication
Language
English
Pages
51
Time to read
8 mins
Publication
Language
English
This document is a technical report detailing the unique characteristics and requirements of security-sensitive users, particularly in the context of hacking and vulnerability research. It begins by defining the target users and discussing their specific needs and contexts, emphasizing the importance of understanding these factors for effective research. The report outlines the motivations behind hacking and the processes of vulnerability discovery, including both attack and responsible disclosure approaches. It discusses the bug bounty ecosystem, identifying stakeholders and the advantages of involving external hackers in finding vulnerabilities. The document also examines the challenges faced by hackers, such as poor responsiveness from vendors and issues related to gig work. Furthermore, it presents insights into the bug bounty ecosystem in China, highlighting the productivity of teams compared to individual hunters, and concludes with the implications of legal concerns impacting security-sensitive users.