Live data from Hacker News

Shopify has paid over $300k in security exploit bounties

hackerone.com

61–70 of 80 posts

Re: Shopify has paid over $300k in security exploit bounties

#61

I don't know if it's the right place, but does anyone has feedbacks regarding the Hacker One platform? Especially for small SaaS (between 1-2M ARR)?

As someone who has used hackerone on both sides (managing and reporting bugs) I'd suggest starting a private program first. Select a small group of researches known to provide good reports and wait for them to start rolling in. Use this as a pilot, if you see value in what's being reported keep it open. Keep in mind you're going to see a lot of reports in the beginning, it will level off as you apply fixes. You'll ne…

+1 to starting a private program first which is recommended by all bounty programs.

If helpful I wrote down my notes about starting a bounty program although my experiences were formed by larger companies https://medium.com/@collingreene/bug-bounty-5-years-in-c95cd...

Re: Shopify has paid over $300k in security exploit bounties

#62
post #57
post #49

Earlier quoted context omitted.

I strongly urge you to find security management people at existing startups to talk to before starting a bug bounty program at your own startup. There are things about them that are good, but those things can be counterintuitive. I haven't had to manage one (yet), but because we'll no doubt be doing that for several startups this year I've been talking to friends about what their bounty programs have been like, and I…

> Frankly, bounties are something I might push back on for a lot of startups. Care to elaborate why?

If you introduce a bug bounty too early, you will be paying out for vulnerabilities that could be caught or prevented in a much more cost effective manner (vulnerability assessments, penetration tests, developer training, appropriate monitoring).

Daniel Miessler has a good breakdown of when to consider various types of security testing: https://danielmiessler.com/blog/when-vulnerability-assessmen...

Sqreen also have a handy basic security checklist: http://cto-security-checklist.sqreen.io Specific to bug bounties they say "You need security aware people inside your development teams to evaluate any reports you receive."

Re: Shopify has paid over $300k in security exploit bounties

#63

Earlier quoted context omitted.

So I'd be interested to know your thoughts on bug bounties as against "traditional" security reviews. Have these areas of your application been through external reviews before being opened up to bug bounty or did you decide to start there? I was thinking that for the amount you've paid out in bounties you could've engaged a reasonable team for several man-months, so was interested in what led you more down the bug bo…

You seem to assume we set out to pay this amount to begin with. Indeed for this amount we could have went other ways, but hindsight is 20/20. No one expected to get so many valid sumbmissions in such a short time. We set the payout amounts this high as a way to attract talent at the beginning of the program, which worked quite well to bootstrap it.

I literally just got off the phone with Hacker One on Friday and they recommend the exact OPPOSITE of what you did. Start with low or no bounty to get the easy stuff off the plate and figure out what class of reports you want -- then ramp up the bounty over time.

Which is what we'll be doing!

Re: Shopify has paid over $300k in security exploit bounties

#65

I don't know if it's the right place, but does anyone has feedbacks regarding the Hacker One platform? Especially for small SaaS (between 1-2M ARR)?

Agreed with others that it's worth considering a small private program. You can do time boxed bounties with a capped cost, that way you're getting results without committing to a huge budget. Check out Bugcrowd's "on demand" bounty: https://bugcrowd.com/solutions

Re: Shopify has paid over $300k in security exploit bounties

#66
post #3

we expect most vulnerabilities will no longer be exploitable without additional bugs in the kernel or seccomp itself, and so we are lowering the payout amounts for our program to 10% of previous levels. I don't quite follow this logic. If bugs are now going to be more difficult to find, one would think they would be more valuable, not less.. and that by lowering the bounties they are lowering the incentive for people…

More expensive to discover, but less valuable to discover. It's harder for white hats to find them, so you gotta pay more if it's important, but it's also harder for blackhats to find them, so it's less pressing to find them quickly.

Re: Shopify has paid over $300k in security exploit bounties

#67

about a year's salary for a security-focused engineer. Did they get more or less bang for their buck? I guess we need to ask haquaman how many hours he spent in collecting that $49k (by my count)

I spent 3 days on it and collected $70k. Per hour that's near a top lawyer :P

Re: Shopify has paid over $300k in security exploit bounties

#68
What's funny is Facebook -> has a publically faced image server that has NO authentication required to see even private messages. When FB Security was contacted ... they say it was not a "guessable" URL, ergo security through obscurity was their "security method" of choice. This was two days ago.

If anyone wants to test this theory - setup 2 FB accounts, message an image one FB account to the other. Click on the image with the second account (to bring up the lightbox custom thingy they have). Drag that image into notepad (to get the URL)... then try and logout of both accounts, clear your cache, and you'll see the image is COMPLETELY public -> meaning no authentication is required.

They refused to acknowledge this as a "security risk". I laughed, then was really pissed that a PRIVATE image shared between two parties can be viewed w/o authentication above it.

WTF?

Re: Shopify has paid over $300k in security exploit bounties

#69
post #67

about a year's salary for a security-focused engineer. Did they get more or less bang for their buck? I guess we need to ask haquaman how many hours he spent in collecting that $49k (by my count)

I spent 3 days on it and collected $70k. Per hour that's near a top lawyer :P

Were you recruited to work on the bounty?
Post reply on HN