A bug bounty is a program in which an organisation pays independent security researchers for finding and responsibly reporting vulnerabilities in its products or services.
How bug bounty programs work
The company publishes rules: which systems are in scope, which testing methods are forbidden (for example denial of service or access to real customer data), how to report findings and how much each class of vulnerability is worth. Researchers test, submit reports, and the vendor verifies, fixes and pays. A “safe harbour” clause promises not to take legal action against researchers who follow the rules.
Many programs run on platforms such as HackerOne, Bugcrowd and Intigriti, which handle triage and payments. Rewards range from a few hundred dollars for minor bugs to six- or seven-figure sums for critical remote code execution chains in browsers or mobile operating systems.
A short history
Netscape launched one of the first bug bounties in 1995 for its Navigator browser. Google started its Vulnerability Reward Program in 2010 and now pays out millions of dollars a year, and in 2016 the US Department of Defense ran “Hack the Pentagon”, the first bounty of the federal government. Competitions such as Pwn2Own and exploit brokers like the Zero Day Initiative work on similar principles.
Why bug bounties matter
Bounties give researchers a legal, paid alternative to selling zero-day exploits on the grey market, and they bring thousands of diverse testers to a company’s systems. They complement, but do not replace, internal security reviews and penetration testing.
Best practices
Start with a vulnerability disclosure policy, define a clear scope, respond quickly, and fix root causes rather than single reports.