Live data from Hacker News

Heroku Security Bug Bounty

blog.heroku.com

1–8 of 8 posts

Re: Heroku Security Bug Bounty

#3
> As part of Heroku and our parent company Salesforce.com’s commitment to philanthropy, if you are interested in donating your bounty to a recognized charity we will match it dollar-for-dollar.

Kudos to the Heroku folks for this. I haven't seen any other bug bounty program doing this (I'd love to be wrong -- please let me know if I am!), and it's a very nice change from the norm.

Re: Heroku Security Bug Bounty

#4
post #3

> As part of Heroku and our parent company Salesforce.com’s commitment to philanthropy, if you are interested in donating your bounty to a recognized charity we will match it dollar-for-dollar. Kudos to the Heroku folks for this. I haven't seen any other bug bounty program doing this (I'd love to be wrong -- please let me know if I am!), and it's a very nice change from the norm.

Yes! Reading that part put a smile on my face.

Re: Heroku Security Bug Bounty

#5
post #3

> As part of Heroku and our parent company Salesforce.com’s commitment to philanthropy, if you are interested in donating your bounty to a recognized charity we will match it dollar-for-dollar. Kudos to the Heroku folks for this. I haven't seen any other bug bounty program doing this (I'd love to be wrong -- please let me know if I am!), and it's a very nice change from the norm.

Google also match anyone who donates their bounty to charity.

Re: Heroku Security Bug Bounty

#6
post #2

I wonder why they chose BugCrowd over the seemingly significantly cheaper HackerOne?

I would guess it is precisely because BugCrowd is more expensive. They offer a managed program where BugCrowd's employees validate bug reports for participating companies. Speaking from experience, that process can become very time-consuming.

Re: Heroku Security Bug Bounty

#7
post #3

> As part of Heroku and our parent company Salesforce.com’s commitment to philanthropy, if you are interested in donating your bounty to a recognized charity we will match it dollar-for-dollar. Kudos to the Heroku folks for this. I haven't seen any other bug bounty program doing this (I'd love to be wrong -- please let me know if I am!), and it's a very nice change from the norm.

[deleted]

Re: Heroku Security Bug Bounty

#8
post #2

I wonder why they chose BugCrowd over the seemingly significantly cheaper HackerOne?

I would guess it is precisely because BugCrowd is more expensive. They offer a managed program where BugCrowd's employees validate bug reports for participating companies. Speaking from experience, that process can become very time-consuming.

If I were running a startup or even a moderately-sized company, implementing and managing a bug bounty program internally sounds like a headache, and probably would be put off indefinitely. A managed solution like BugCrowd could definitely fill this void.