Uber Offers Hackers 'Treasure Map' to Find Bugs in Its Systems

Advertisement
By Reuters | Updated: 23 March 2016 09:51 IST

Uber, the high-flying transportation firm, is releasing a technical map of its computer and communications systems and inviting hackers to find weaknesses in exchange for cash bounties.

While so-called "bug bounties" are not new, Uber's move shows how mainstream companies are increasingly relying on independent computer researchers to help them bolster their systems. It also indicates growing acceptance of the idea that making computer code public can make systems more secure, a philosophy that has long been advocated by the open-source software movement.

Uber's "Treasure Map" details the ride-hailing company's software infrastructure, identifies what sorts of data might be exposed inadvertently and suggests what types of flaws are the most likely to be found.

Advertisement

"We're wrapping up a lot of information and posting that to level the playing field so that it could be as easy for outside researchers to find flaws as us," said Collin Greene, manager of security engineering at Uber.

Advertisement

Companies rarely say much about their proprietary programming, except to enable third parties to make compatible software.

"That's a level of confidence that you have not seen too many closed-source software companies take in the past, and I'm really hopeful that others will follow suit," said Alex Rice, chief technology officer at HackerOne, which is managing Uber's bounty program.

Advertisement

HackerOne, a San Francisco rival called Bugcrowd and other startups have helped accelerate efforts to tap the independent security community to identify serious programming mistakes before criminals or spies do. They can serve as intermediaries between researchers and companies, and sometimes vet their findings.

A decade ago, hackers pointing out problems feared arrest but they can now earn modest sums from platforms like HackerOne. Firms such as Uber, looking to bolster their defenses, don't pay as much as criminals and military contractors who are looking for tools to carry out offensive attacks, but they offer options to those who would prefer to act as "white hats."

Advertisement

Bugcrowd Chief Executive Officer Casey Ellis said he has seen a surge in corporate clients asking for private bounty programs that are open to selected researchers.

"That increases the amount of trust you are giving to the researchers," Ellis said. "We run trusted programs where people get prerelease versions of Internet of Things devices or access to source code."

© Thomson Reuters 2016

 

For details of the latest launches and news from Samsung, Xiaomi, Realme, OnePlus, Oppo and other companies at the Mobile World Congress in Barcelona, visit our MWC 2025 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus 15T Confirmed to Launch With a Larger Battery, Faster Charging
  2. Lava Bold 2 5G India Launch Teased; Company Teases Design Ahead of Debut
  3. Moto Watch Review: The Best Smartwatch Under Rs. 6,000 in 2026?
  4. OnePlus 16, iQOO 16, Redmi K100 Pro Max Tipped to Launch at Higher Prices
  5. Oppo Find N6 Key Features, Colourways Leaked Ahead of Imminent China Launch
  6. Samsung May Be Working on a Foldable With This Unique Display Feature
  7. Vivo T5x 5G AnTuTu Score Exceeds 1 Million Points, Will Launch in India Soon
  1. ISS Crew Prepares to Send Japan’s HTV-X1 Cargo Spacecraft Back to Earth After Four Months
  2. OpenAI’s Codex App Is Now Available on Windows, Can Be Downloaded via Microsoft Store
  3. OpenAI Teases GPT-5.4 AI Model Launch Just a Day After Releasing GPT-5.3 Instant
  4. Nothing Headphone (a) Launched With Adaptive ANC, Customisable Controls: Price, Specifications
  5. Granny OTT Release Date: When and Where to Watch the Village Mystery Thriller Online?
  6. Andhaka OTT Release: Where to Watch the Telugu Drama-Thriller Online?
  7. Pookie OTT Release: When and Where to Watch Vijay Antony’s Romantic Drama Online?
  8. WhatsApp Plus Paid Subscription Reportedly in Development With Additional Customisation Options, Up to 20 Pinned Chats
  9. Samsung Patent Hints at Potential Clamshell-Style Foldable With Two Cover Displays
  10. Google Introduces Gemini 3.1 Flash-Lite as Its Fastest and Most Cost-Efficient AI Model
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.