Bug Bounties and Vulnerability Disclosure Program (VDP) are one of the fastest growing, most popular ways for companies to engage with the security research community and uncover unknown security vulnerabilities. They also raise a variety of legal issues for researchers and corporations to consider. This talk will explore how the law interacts with bug bounties and VDP, how it might affect security researchers, and suggest pathways for bug bounties and vulnerability disclosure programs to foster research and ethical hacking. Highlights will include anti-hacking laws, unpacking some myths concerning bug bounties legalese, and contract standardization efforts already widely adopted across the industry.