Uber Offers Hackers 'Treasure Map' to Find Bugs in Its Systems

Advertisement
By Reuters | Updated: 23 March 2016 09:51 IST
Uber Offers Hackers 'Treasure Map' to Find Bugs in Its Systems

Uber, the high-flying transportation firm, is releasing a technical map of its computer and communications systems and inviting hackers to find weaknesses in exchange for cash bounties.

While so-called "bug bounties" are not new, Uber's move shows how mainstream companies are increasingly relying on independent computer researchers to help them bolster their systems. It also indicates growing acceptance of the idea that making computer code public can make systems more secure, a philosophy that has long been advocated by the open-source software movement.

Uber's "Treasure Map" details the ride-hailing company's software infrastructure, identifies what sorts of data might be exposed inadvertently and suggests what types of flaws are the most likely to be found.

"We're wrapping up a lot of information and posting that to level the playing field so that it could be as easy for outside researchers to find flaws as us," said Collin Greene, manager of security engineering at Uber.

Advertisement

Companies rarely say much about their proprietary programming, except to enable third parties to make compatible software.

"That's a level of confidence that you have not seen too many closed-source software companies take in the past, and I'm really hopeful that others will follow suit," said Alex Rice, chief technology officer at HackerOne, which is managing Uber's bounty program.

Advertisement

HackerOne, a San Francisco rival called Bugcrowd and other startups have helped accelerate efforts to tap the independent security community to identify serious programming mistakes before criminals or spies do. They can serve as intermediaries between researchers and companies, and sometimes vet their findings.

A decade ago, hackers pointing out problems feared arrest but they can now earn modest sums from platforms like HackerOne. Firms such as Uber, looking to bolster their defenses, don't pay as much as criminals and military contractors who are looking for tools to carry out offensive attacks, but they offer options to those who would prefer to act as "white hats."

Advertisement

Bugcrowd Chief Executive Officer Casey Ellis said he has seen a surge in corporate clients asking for private bounty programs that are open to selected researchers.

"That increases the amount of trust you are giving to the researchers," Ellis said. "We run trusted programs where people get prerelease versions of Internet of Things devices or access to source code."

© Thomson Reuters 2016

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. BSNL Announces Flash Sale in India With Free Data, Discounts
  2. Samsung Galaxy M36 5G Launching Today: All You Need to Know
  3. Nothing Phone 3 Renders Leaked Ahead of July 1 Launch
  4. Vivo X200 FE India Launch Teased; Key Specifications Revealed
  5. OTT Releases of the Week: Squid Game S3, Raid 2, Panchayat S4, and More
  6. YouTube's New Search Feature Will Remind You of Google's AI Overviews
  7. Xiaomi AI Glasses With 12-Megapixel Camera Launched at This Price
  8. Here Are The Best Deals of Steam Summer Sale 2025
  9. Xiaomi's Pad 7S Pro With Xring O1 Processor Launched: All Details
  10. Redmi K Pad With 8.8-Inch Display, 7,500mAh Battery Unveiled: See Details
  1. Samsung Galaxy M36 5G Launched in India With Exynos 1380 SoC, 5,000mAh Battery
  2. Maaman Now Available for Streaming on Z5: Everything You Need to Know
  3. Kaalidhar Laapata OTT Release Date: When and Where to Watch Abhishek Bachchan Starrer Online?
  4. Ironheart Streaming Now: What You Need to Know About Latest Marvel Mini Series
  5. Microsoft to Replace Blue Screen of Death With Simpler Black Eror Screen Later This Year
  6. YouTube Introduces AI-Powered Search Results Carousel, Shows a Snapshot of Suggested Videos
  7. Vivo X200 FE Teased to Launch in India Soon; Key Specifications Revealed
  8. Xiaomi Pad 7S Pro With12.5-Inch Display and Xring O1 Processor Launched: Price, Specifications
  9. Xiaomi Watch S4 41mm With AMOLED Screen Launched Alongside Smart Band 10: Price, Specifications
  10. Google Releases Gemma 3n Open-Source AI Model That Can Run Locally on 2GB RAM
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.