Twitter launches bug bounty program

The company will pay researchers at least $140 for privately reporting serious vulnerabilities in its Web services and mobile apps

Following in the footsteps of other major Internet companies, Twitter has started paying monetary rewards to security researchers who find and report vulnerabilities in its Web services and mobile apps.

In recent years, bug bounty programs have become a popular complement to internal code security reviews and penetration tests.

Google was one of the first companies to launch a vulnerability reward program that covered its online properties in 2010. It's since been joined by Facebook, PayPal, Yahoo and Mozilla.

"We're introducing a bug bounty program to thank researchers for responsibly-disclosed issues," Twitter said Wednesday through its Twitter Security account.

The company has opted to run its program through a third-party bug reporting platform called HackerOne that's also used by Yahoo, CloudFlare, Automattic and other companies.

HackerOne also runs the Internet Bug Bounty, a program sponsored by Microsoft and Facebook that rewards researchers for finding vulnerabilities in software considered critical to the Internet infrastructure like the OpenSSL library, the Apache and Nginx Web servers and the Ruby, Python, PHP and Perl programming languages.

According to its page on HackerOne, Twitter will pay at least $140 per vulnerability found in its twitter.com services or iOS and Android apps. The reward amounts may vary depending on the severity of the reported flaws and there is no predefined limit to how high they can get, Twitter said.

Vulnerabilities that qualify for bounties under Twitter's program are those that result in cross-site scripting (XSS), cross-site request forgery (CSRF), remote code execution (RCE) or unauthorized access to protected tweets and direct messages.

Even though the official program with monetary rewards just launched, Twitter has been using HackerOne since May, during which time it has patched over 40 bugs reported through the platform. Prior to this, the only public recognition it gave to researchers who directly reported flaws to the company was listing them on its security page.

Bug bounty programs "are a great tool -- if done right -- for companies to control the disclosure process and encourage researchers to come to them with their findings," said Carsten Eiram, the chief research officer at Risk Based Security via email on Thursday. "It's also being used a lot as a PR tool to show that the company cares about security and working with researchers."

Eiram and Risk Based Security CISO Jake Kouns held a presentation about the evolution of bug bounty programs and how they motivate researchers at the DefCon security conference in August.

"I generally recommend most major companies with a SaaS [software-as-a-service] solution to have a bug bounty program in place," Eiram said. "Even smaller companies should consider it, and there are a lot of different options available, fitting the various sizes of companies and their wallets. Using platforms like HackerOne, Bugcrowd, or CrowdCurity can make the whole process easier to manage vs. creating one's own program from scratch."

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags patchesonline safetysecuritytwitterExploits / vulnerabilities

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Lucian Constantin

IDG News Service
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

David Coyle

Brother PocketJet PJ-773 A4 Portable Thermal Printer

I rate the printer as a 5 out of 5 stars as it has been able to fit seamlessly into my busy and mobile lifestyle.

Kurt Hegetschweiler

Brother PocketJet PJ-773 A4 Portable Thermal Printer

It’s perfect for mobile workers. Just take it out — it’s small enough to sit anywhere — turn it on, load a sheet of paper, and start printing.

Featured Content

Product Launch Showcase

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?