Menu
Twitter launches bug bounty program

Twitter launches bug bounty program

The company will pay researchers at least $140 for privately reporting serious vulnerabilities in its Web services and mobile apps

Following in the footsteps of other major Internet companies, Twitter has started paying monetary rewards to security researchers who find and report vulnerabilities in its Web services and mobile apps.

In recent years, bug bounty programs have become a popular complement to internal code security reviews and penetration tests.

Google was one of the first companies to launch a vulnerability reward program that covered its online properties in 2010. It's since been joined by Facebook, PayPal, Yahoo and Mozilla.

"We're introducing a bug bounty program to thank researchers for responsibly-disclosed issues," Twitter said Wednesday through its Twitter Security account.

The company has opted to run its program through a third-party bug reporting platform called HackerOne that's also used by Yahoo, CloudFlare, Automattic and other companies.

HackerOne also runs the Internet Bug Bounty, a program sponsored by Microsoft and Facebook that rewards researchers for finding vulnerabilities in software considered critical to the Internet infrastructure like the OpenSSL library, the Apache and Nginx Web servers and the Ruby, Python, PHP and Perl programming languages.

According to its page on HackerOne, Twitter will pay at least $140 per vulnerability found in its twitter.com services or iOS and Android apps. The reward amounts may vary depending on the severity of the reported flaws and there is no predefined limit to how high they can get, Twitter said.

Vulnerabilities that qualify for bounties under Twitter's program are those that result in cross-site scripting (XSS), cross-site request forgery (CSRF), remote code execution (RCE) or unauthorized access to protected tweets and direct messages.

Even though the official program with monetary rewards just launched, Twitter has been using HackerOne since May, during which time it has patched over 40 bugs reported through the platform. Prior to this, the only public recognition it gave to researchers who directly reported flaws to the company was listing them on its security page.

Bug bounty programs "are a great tool -- if done right -- for companies to control the disclosure process and encourage researchers to come to them with their findings," said Carsten Eiram, the chief research officer at Risk Based Security via email on Thursday. "It's also being used a lot as a PR tool to show that the company cares about security and working with researchers."

Eiram and Risk Based Security CISO Jake Kouns held a presentation about the evolution of bug bounty programs and how they motivate researchers at the DefCon security conference in August.

"I generally recommend most major companies with a SaaS [software-as-a-service] solution to have a bug bounty program in place," Eiram said. "Even smaller companies should consider it, and there are a lot of different options available, fitting the various sizes of companies and their wallets. Using platforms like HackerOne, Bugcrowd, or CrowdCurity can make the whole process easier to manage vs. creating one's own program from scratch."


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags securitytwitteronline safetypatchesExploits / vulnerabilities

Featured

Slideshows

Meet the leading female front runners of the Kiwi channel

Meet the leading female front runners of the Kiwi channel

Reseller News honoured the leading female front runners of the New Zealand channel at the 2018 Women in ICT Awards (WIICTA) in Auckland. The awards honoured standout individuals across seven categories, spanning Entrepreneur; Innovation; Rising Star; Shining Star; Community; Technical and Achievement.

Meet the leading female front runners of the Kiwi channel
Meet the top performing customer-centric Microsoft channel partners

Meet the top performing customer-centric Microsoft channel partners

Microsoft honoured leading partners across the channel following a year of customer innovation and market growth in New Zealand. The 2018 Microsoft Partner Awards recognised excellence within the context of the end-user, spanning a host of emerging and established providers.

Meet the top performing customer-centric Microsoft channel partners
Reseller News launches new-look Awards at 2018 Judges’ Lunch

Reseller News launches new-look Awards at 2018 Judges’ Lunch

Introducing the Reseller News Innovation Awards, launched to the channel at the 2018 Judges’ Lunch in Auckland. With more than 70 judges now part of the voting panel, the new-look awards will reflect the changing dynamics of the channel, recognising excellence across customer value and innovation - spanning start-ups, partners, distributors and vendors.

Reseller News launches new-look Awards at 2018 Judges’ Lunch
Show Comments