Story image

GitHub boosts bug bounty program & payouts in 2017 with more to come this year

19 Mar 18

GitHub’s Security Bug Bounty program paid out more than US$166,000 in 2017 after a significant payout revamp that doubled amounts across the board.

Last month the company marked the fourth year of its program and it says 2017 was its ‘biggest year yet’.

It reviewed and triaged 840 bug submissions, or which 121 were resolved and rewarded. The average payout netted bug reporters US$1376. 

The company says the numbers represent a 15% increase in valid bug reports compared to 48 of 795 incidents resolved in 2016.

GitHub senior manager of security engineering Greg Ose says in a blog post that the total reward payouts rose to $166,495 in 2017 – up from $95,300 in 2016.

“We attribute this to the increased number of valid reports and in October we took time to re-evaluate our payout structure. Corresponding with HackerOne's Hack the World competition, we doubled our payout amounts across the board, bringing our minimum and maximum payouts to $555 and $20,000, bringing our bug bounty in line with the industry's top programs.”

GitHub also conducted a number of other initiatives to boost the Security Bug Bounty program.

One of these was the introduction of GitHub enterprise, which allowed researchers to look at areas specific to enterprise or applications not exposed on GitHub.

“A number of reports impacting our enterprise authentication methods prompted us to not only focus on this internally, but also identify how we could engage researchers to focus on this functionality,” Ose explains.

The company also offered one researcher a grant to research a specific feature or areas of application. Bug bounty rewards also applied.

“During the beginning of the year, we identified a researcher with specialty in assessing troublesome enterprise authentication methods. We reached out and launched our first researcher grant. We couldn't have been happier with the results. It provided a depth of expertise and review that was well worth the extra monetary incentive,” Ose says.

Off the back of its GitHub for Business launch, the company rolled out private bug bounties through a private program on HackerOne.

“We reached out to all researchers who had previously participated in our program and allowed them access to this functionality before its public launch. This added to our internal pre-ship security assessments with review by external researchers and helped us identify and remediate issues before general exposure. With the extra review, we were able to limit the impact of vulnerabilities in production while also providing fresh code and functionality for researchers to look into.”

Finally, the company has continued to develop its HackerOne API client and internal improvements to triage and implement submissions from its bounty reporters.

For the year ahead Ose says, “We'll be launching more private bounties and research grants to gain focus on specific features both before and after they publicly launch. Later in the year, we'll announce additional promotions to continue to keep researchers interested and excited to participate.”

JASK prepares for global rollout of their AI-powered ASOC platform
The JASK ASOC platform automates alert investigations, supposedly freeing the SOC analyst to do what machines can’t. 
Pitfalls to avoid when configuring cloud firewalls
Flexibility and granularity of security controls is good but can still represent a risk for new cloud adopters that don’t recognise some of the configuration pitfalls.
Securing hotel technology to protect customer information
Network security risks increase exponentially as hotels look to incorporate newer technologies to support a range of IoT devices, including smart door locks.
Why total visibility is the key to zero trust
Over time, the basic zero trust model has evolved and matured into what Forrester calls the Zero Trust eXtended (ZTX) Ecosystem.
Gartner names Proofpoint Leader in enterprise information archiving
The report provides a detailed overview of the enterprise information archiving market and evaluates vendors based on completeness of vision and ability to execute.
WatchGuard appoints new channel distributors in A/NZ
The appointments will enable WatchGuard to expand its regional channel reseller footprint.
Tensions on the rise after Huawei CFO arrest
“Recently our corporate CFO, Meng Wanzhou, was provisionally detained by the Canadian authorities on behalf of the United States of America."
Palo Alto Networks integrates RedLock and VM-Series with AWS Security Hub
AWS Security Hub is designed to provide users with a comprehensive view of their high-priority security alerts and compliance status.