This wasn't unexpected outside of the extend of the bounties. What you have to realize is how important Security is to Shopify. We are a trust based business to an extreme extend. We host the livelihoods of hundreds of thousands of other businesses. If we are down or compromised all of them can't make money ( as some of you saw during Black Friday, to the tune of $300k+ a minute at times ). One of the best ways for u…
So I'd be interested to know your thoughts on bug bounties as against "traditional" security reviews. Have these areas of your application been through external reviews before being opened up to bug bounty or did you decide to start there? I was thinking that for the amount you've paid out in bounties you could've engaged a reasonable team for several man-months, so was interested in what led you more down the bug bo…
Doubt that.
1) The daily rate for this kind of work is high.
2) It's hard to find people who can execute. (read: security as in pen testing, not security as in filling a PCI compliance checklist).
3) Multiply 1 and 2 by the number of people you want in the team.