Twitter pays $322,420 to bug hunters

Author: agencies/online

NEW YORK: Micro-blogging website Twitter has paid $322,420 to researchers and bug hunters who, under its bug bounty “HackerOne” program, have disclosed vulnerabilities in the last two years.

“We maintain a secure development lifecycle that includes secure development training to everyone that ships code, security review processes, hardened security libraries and robust testing through internal and external services – all to maximise the security we provide to our users,” software engineer at Twitter Arkadiy Tetelman said in a blog post on Friday.

On top of these measures, the company also engages the broader information security community through their bug bounty program, allowing security researchers to responsibly disclose vulnerabilities to the company so that they can respond and address these issues before they are exploited by others.

The company has been utilising “HackerOne” since May 2014 and has found the program to be an invaluable resource for finding and fixing security vulnerabilities ranging from the mundane to severe, Tetelman added.

He noted that in two years, the company has received 5,171 submissions to the program from 1,662 researchers and 20 per cent of resolved bugs at the request of the researcher were publicly disclosed.

“We have paid out a total of $322,420 to researchers. Our average pay out is $835. Our minimum pay-out is $140 and our highest pay-out to date was $12,040 (our pay-outs are always a multiple of 140),” Tetelman noted.

In 2015 alone, a single researcher made over $54,000 for reporting vulnerabilities, the software engineer said.

“We also offer a minimum of $15,000 for remote code execution vulnerabilities, but we have yet to receive such a report,” he added.

Tetelman noted some great bugs exposed through the program, including XSS inside Crashlytics Android app that renders part of its content inside a web view, which did not have adequate protection against cross site scripting attacks.

He also mentioned “Illinois Department of Revenue (IDOR) allowing credit card deletion” – a simple insecure direct object reference bug on the credit card deletion endpoint allowed an attacker to delete, but not view, credit cards not belonging to them.

“If you are interested in helping keep Twitter safe and secure too then head on over to our bug bounty program, or apply to one of our open security positions!” he said.

Share
Leave a Comment

Recent Posts

  • Pakistan

Punjab starts implementing plan to combat smog

The Punjab government has initiated implementation of a comprehensive strategy to combat environmental pollution and…

10 hours ago
  • Pakistan

Apni Chhat, Apna Ghar: CM Maryam approves 3-marla plot scheme

Punjab Chief Minister Punjab Maryam Nawaz Sharif has approved a scheme to provide three-marla plots…

10 hours ago
  • Pakistan

Seven outlaws arrested, weapons recovered

The Islamabad Capital Territory (ICT) Police on Saturday apprehended seven criminals involved in various illegal…

10 hours ago
  • Pakistan

DC inaugurates 7th agricultural population census

Deputy Commissioner Larkana Dr. Sharjeel Noor Channa has inaugurated the 7th Agricultural Population Census. The…

10 hours ago
  • Pakistan

PTI arming ‘youth force activists and Afghan nationals,’ says Azma

Punjab's Information Minister Azma Bokhari has accused the Pakistan Tehreek-e-Insaf (PTI) of arming activists and…

10 hours ago
  • Pakistan

Danyal says PTI’s political decline exposed before people

Parliamentary Secretary for Information and Broadcasting, Barrister Daniyal Chaudhry, blasted PTI's political decline, saying Bushra…

10 hours ago