Close Menu
Innovation Village | Technology, Product Reviews, Business
    Facebook X (Twitter) Instagram
    Sunday, October 12
    • About us
      • Authors
    • Contact us
    • Privacy policy
    • Terms of use
    • Advertise
    • Newsletter
    • Post a Job
    • Partners
    Facebook X (Twitter) LinkedIn YouTube WhatsApp
    Innovation Village | Technology, Product Reviews, Business
    • Home
    • Innovation
      • Products
      • Technology
      • Internet of Things
    • Business
      • Agritech
      • Fintech
      • Healthtech
      • Investments
        • Cryptocurrency
      • People
      • Startups
      • Women In Tech
    • Media
      • Entertainment
      • Gaming
    • Reviews
      • Gadgets
      • Apps
      • How To
    • Giveaways
    • Jobs
    Innovation Village | Technology, Product Reviews, Business
    You are at:Home»Internet»Twitter Has Paid $322,420 to Bug Hunters So Far
    twitter

    Twitter Has Paid $322,420 to Bug Hunters So Far

    0
    By Chidi on May 30, 2016 Internet, Social Media

    Micro-blogging website Twitter has paid $322,420 to researchers and bug hunters who, under its bug bounty “HackerOne” program, have disclosed vulnerabilities in the last two years.

    “We maintain a secure development life-cycle that includes secure development training to everyone that ships code, security review processes, hardened security libraries and robust testing through internal and external services, all to maximise the security we provide to our users,” Arkadiy Tetelman, software engineer at Twitter, said in a blog post on Friday.

    The company also engages the broader information security community through their bug bounty program, allowing security researchers to responsibly disclose vulnerabilities to the company so that they can respond and address these issues before they are exploited by others.

    The company has utilised “HackerOne” since May 2014 and has found the program to be an invaluable resource for finding and fixing security vulnerabilities ranging from the mundane to severe, Tetelman added.

    He noted that in two years, the company has received 5,171 submissions to the program from 1,662 researchers and 20 percent of resolved bugs were publicly disclosed (at the request of the researcher).

    “We have paid out a total of $322,420 (USD) to researchers. Our average payout is $835. Our minimum payout is $140 and our highest payout to date was $12,040 (our payouts are always a multiple of 140),” Tetelman noted.

    In 2015 alone, a single researcher made over $54,000 for reporting vulnerabilities, the software engineer said.

    “We also offer a minimum of $15,000 for remote code execution vulnerabilities, but we have yet to receive such a report,” he added.

    He also mentioned “IDOR allowing credit card deletion” — a simple insecure direct object reference bug on the credit card deletion endpoint allowed an attacker to delete, but not view, credit cards not belonging to them.

    “If you are interested in helping keep Twitter safe and secure too then head on over to our bug bounty program, or apply to one of our open security positions!” he said

    Related

    Twitter
    Share. Facebook Twitter Pinterest LinkedIn Email
    Chidi
    • Website
    • Facebook
    • X (Twitter)

    Tech & Gadget enthusiast | Apple fan | Sci-fi/Music lover | Software engineer

    Related Posts

    Chrome adds auto-revocation for notification permissions in latest update

    Musk settles $128m severance lawsuit with Twitter’s former top brass — terms undisclosed

    Google’s New AI App Builder Opal Is Going Global — But Not in Africa (Yet)

    Leave A Reply Cancel Reply

    You must be logged in to post a comment.

    Copyright ©, 2013-2024 Innovation-Village.com. All Rights Reserved

    Type above and press Enter to search. Press Esc to cancel.