Twitter Has Paid Out $322,420 in Its 'HackerOne' Bug Bounty Programme

Advertisement
By Indo-Asian News Service | Updated: 28 May 2016 16:46 IST
Twitter Has Paid Out $322,420 in Its 'HackerOne' Bug Bounty Programme
Micro-blogging website Twitter has paid $322,420 (roughly Rs. 2.1 crores) to researchers and bug hunters who, under its bug bounty "HackerOne" program, have disclosed vulnerabilities in the last two years.

"We maintain a secure development lifecycle that includes secure development training to everyone that ships code, security review processes, hardened security libraries and robust testing through internal and external services - all to maximise the security we provide to our users," Arkadiy Tetelman, software engineer at Twitter, said in a blog post on Friday.

On top of these measures, the company also engages the broader information security community through their bug bounty program, allowing security researchers to responsibly disclose vulnerabilities to the company so that they can can respond and address these issues before they are exploited by others.

The company has been utilising "HackerOne" since May 2014 and has found the program to be an invaluable resource for finding and fixing security vulnerabilities ranging from the mundane to severe, Tetelman added.

He noted that in two years, the company has received 5,171 submissions to the program from 1,662 researchers and 20 percent of resolved bugs were publicly disclosed (at the request of the researcher).

Advertisement

"We have paid out a total of $322,420 (USD) to researchers. Our average payout is $835. Our minimum payout is $140 and our highest payout to date was $12,040 (our payouts are always a multiple of 140)," Tetelman noted.

In 2015 alone, a single researcher made over $54,000 (roughly Rs. 36 lakhs) for reporting vulnerabilities, the software engineer said.

Advertisement

"We also offer a minimum of $15,000 (roughly Rs. 10 lakhs) for remote code execution vulnerabilities, but we have yet to receive such a report," he added.

Tetelman noted some great bugs exposed through the program, including XSS inside Crashlytics Android app that renders part of its content inside a webview, which did not have adequate protection against cross site scripting attacks.

Advertisement

He also mentioned "IDOR allowing credit card deletion" -- a simple insecure direct object reference bug on the credit card deletion endpoint allowed an attacker to delete, but not view, credit cards not belonging to them.

"If you are interested in helping keep Twitter safe and secure too then head on over to our bug bounty program, or apply to one of our open security positions!" he said.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo Reno 14 Pro 5G Series Set to Launch in India on This Date
  2. Nothing Phone 3 to Get 50-Megapixel Periscope Telephoto Camera
  3. Samsung Smart Monitor M9 Launched Alongside Updated M8 and M7 Models
  4. iPhone 16 Drops Under Rs. 69,000 With This Offer, Making It a Great Deal
  5. Upcoming Phones in July: Samsung Galaxy Z Fold 7, OnePlus Nord 5, More
  6. Nothing Phone 3 Surfaces on Geekbench Ahead of Launch on July 1
  7. Samsung Galaxy Buds Core With Galaxy AI Features Launched in India
  8. Motorola Teases New Phone Launch in India; Could Be the Moto G96 5G
  9. Qualcomm's Snapdragon Elite 2 SoC for Galaxy S26 May Be Made by Samsung
  10. Lumio Arc Projector Teased Ahead of Possible Amazon Prime Day Launch
  1. Axiom Mission 4 Successfully Docks on International Space Station; Shubhanshu Shukla Becomes First Indian to Reach Milestone
  2. Redmi K80 Ultra With Dimensity 9400+ SoC, 7,410mAh Battery Launched: Price, Specifications
  3. Telegram Bot Reportedly Spotted Selling Sensitive Personal Data of Indian Users
  4. Nothing Phone 3 Confirmed to Feature 50-Megapixel Periscope Telephoto Camera
  5. Vodafone Idea Rolls Out New Max Family Plan with Bundled Netflix Subscription: Price, Benefits
  6. Samsung Galaxy Buds Core TWS With ANC, Galaxy AI Features Launched in India: Price, Specifications
  7. iPhone 16 Available at Rs. 68,400 With Cashback Offer, Making It a Great Deal
  8. Xiaomi Mix Flip 2 With Snapdragon 8 Elite SoC, 50W Wireless Charging Launched: Price, Specifications
  9. Anthropic Now Lets Claude Users Build and Share AI-Powered Interactive Apps
  10. Lumio Arc Projector Teased Ahead of Possible Amazon Prime Day Launch
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.