HackerOne develops bug bounty solutions to help organizations reduce the risk of a security incident by working with the world’s largest community of ethical hackers to conduct discreet penetration tests, and operate a vulnerability disclosure or bug bounty program.
12 weeks ago by cakeface
Dominique Adams:
<p>Teen hacker Santiago Lopez from Argentina has become the world’s first white-hat hacker to earn a million dollars from bug bounties.

Lopez a.k.a @try_to_hack (his online moniker) started flagging up security weaknesses to companies via vulnerability coordination and bug bounty platform, HackerOne.

Since embarking on his legal hacking career in 2015, he has reported more than 1,600 security flaws to organisations, including social media platform Twitter and Verizon Media Company, as well as private corporate and government entities.

Inspired by the movie Hackers, Lopez taught himself how to hack watching free online tutorials and reading popular blogs.

At the age of 16 he earned his first bounty of $50 and was motivated to continued hacking after school. He now hacks full-time earning nearly 40 times the average software engineer salary in Buenos Aires…

…Numerous global companies including the US Department of Defense, General Motors, Google, Twitter, GitHub, Nintendo, Lufthansa, Panasonic Avionics, Qualcomm, Starbucks, Dropbox, and Intel have partnered with HackerOne to discover more than 100,000 vulnerabilities and award more than $45m (£34m) in bug bounties.

Luta Security CEO and cybersecurity expert, Katie Moussouris, said that bug bounties although useful weren’t a “silver bullet”. Moussouris, who created the bug bounty at Microsoft, warned that if badly implemented such programmes could see talent leaving organisations in favour of pursuing bug bounties, and thus damage the talent pipeline.</p>

At a guess, the bounty will be distributed on the usual Pareto (power law) curve. Great for some, peanuts for many.
march 2019 by charlesarthur
IssueHunt 🦉 = OSS Development ⚒ + Bounty Program 💰.
IssueHunt is an issue-based bounty platform for open source projects.
Anyone can put a bounty on not only a bug but also on OSS feature requests listed on IssueHunt. Collected funds will be distributed to project owners and contributors.
march 2019 by endorama

