Bug Bounty Programs

The cluster discusses bug bounty programs, including their effectiveness in encouraging responsible vulnerability disclosure, fairness of payouts, company obligations, and comparisons to alternatives like black market sales.

➡️ Stable 0.8x Security
4,715
Comments
20
Years Active
5
Top Authors
#2047
Topic ID

Activity Over Time

2007
1
2008
12
2009
11
2010
32
2011
71
2012
61
2013
370
2014
198
2015
245
2016
332
2017
290
2018
255
2019
284
2020
544
2021
483
2022
316
2023
288
2024
446
2025
415
2026
61

Keywords

SEO US BitTrap security.txt SRD LLM schneier.com OSS BugCrowd HackerOne bounty bug bugs vulnerability paid security pay rewards black market researchers

Sample Comments

tptacek Nov 1, 2016 View on HN

"Offer bug bounties based on actual access" why?

rmc Oct 10, 2013 View on HN

That's one of the points of bug bounty programmes, isn't it?

nickthemagicman Oct 13, 2018 View on HN

They should be giving bug bounties instead!

darepublic May 27, 2020 View on HN

What if I introduce security bugs only to be paid bounty on them later

JetSpiegel Jul 21, 2017 View on HN

There's already an implicit bug bounty. Whoever found this bug got a bounty of millions. Much better than the presence that tech companies pay.

fnordfnordfnord Aug 19, 2013 View on HN

The bug bounty won't cause others to report bugs if they pay in secret.

tinus_hn May 16, 2019 View on HN

Why would companies pay a bug bounty and then expect nothing in return?

AshRolls Sep 28, 2017 View on HN

NEO award large amounts for bug bounty, I find it hard to believe you would go to the trouble of finding bugs without claiming any reward?

DoreenMichele Nov 8, 2021 View on HN

Thanks for your report, we’ve updated the settings. We don’t have an official bounty program but we do sometimes offer them if the issue is severe enough. On this occasion it is not”And that seems to work fine. For ones a little more involved we’ve paid out $50 a few times which they seem happy with and we’re generally ok to pay.This seems like an extremely reasonable approach.

lmm Dec 3, 2013 View on HN

You're not entitled to a bounty just because you found a bug. Some companies offer these bounties and it's good that they do, but that doesn't mean every company is obliged to offer them, or that a company that offers bounties for some bugs is obliged to offer them for all bugs.