Just In
- 14 hrs ago Elon Musk’s X Is Launching a TV App Similar to YouTube for Watching Videos
- 15 hrs ago Qualcomm Reveals Snapdragon X Plus Chip for Laptops: 10 Core CPU, On-Device AI, & Much More
- 15 hrs ago Flipkart Teases “Jaw-Dropping” Discount on iPhone 15: All-Time Low Price Anticipated
- 15 hrs ago President Joe Biden Signs Bill to Ban TikTok in the US: Unless This One Condition is Met
Don't Miss
- Education Cochin Shipyard, IIM Kozhikode Invites Applications For USHUS Program To Support Maritime Startups
- Lifestyle When Is Vikata Sankashti Chaturthi 2024, 27th Or 28th April? Know Date, Puja Muhurat, History, And Significanc
- Movies Pavi Caretaker Box Office Collection Day 1 Prediction: Dileep's Movie Expected To Open Strongly
- Sports Who Won Yesterday's IPL Match 41? SRH vs RCB, IPL 2024 on April 25: Royal Challengers Bangalore End Losing Streak
- Finance Bajaj Group Stock Declares Rs. 60/Share Dividend: Buy Ahead of Record Date On 28 June?
- News MEA Dismisses US Human Rights Report On Manipur As 'Biased And Misinformed'
- Automobiles Royal Enfield Unveils Revolutionary Rentals & Tours Service: Check Out All Details Here
- Travel Escape to Kalimpong, Gangtok, and Darjeeling with IRCTC's Tour Package; Check Itinerary
Twitter has paid $322,420 to bug hunters so far
Micro-blogging website Twitter has paid $322,420 to researchers and bug hunters who, under its bug bounty "HackerOne" program, have disclosed vulnerabilities in the last two years.
"We maintain a secure development lifecycle that includes secure development training to everyone that ships code, security review processes, hardened security libraries and robust testing through internal and external services -- all to maximise the security we provide to our users," Arkadiy Tetelman, software engineer at Twitter, said in a blog post on Friday.
What Will Happen to Your Facebook Account After Your Death
On top of these measures, the company also engages the broader information security community through their bug bounty program, allowing security researchers to responsibly disclose vulnerabilities to the company so that they can can respond and address these issues before they are exploited by others.
The company has been utilising "HackerOne" since May 2014 and has found the program to be an invaluable resource for finding and fixing security vulnerabilities ranging from the mundane to severe, Tetelman added.
He noted that in two years, the company has received 5,171 submissions to the program from 1,662 researchers and 20 percent of resolved bugs were publicly disclosed (at the request of the researcher).
"We have paid out a total of $322,420 (USD) to researchers. Our average payout is $835. Our minimum payout is $140 and our highest payout to date was $12,040 (our payouts are always a multiple of 140)," Tetelman noted.
In 2015 alone, a single researcher made over $54,000 for reporting vulnerabilities, the software engineer said.
"We also offer a minimum of $15,000 for remote code execution vulnerabilities, but we have yet to receive such a report," he added.
Tetelman noted some great bugs exposed through the program, including XSS inside Crashlytics Android app that renders part of its content inside a webview, which did not have adequate protection against cross site scripting attacks.
10 Best Android Smartphones With 2 GB RAM Under Rs 6,000
He also mentioned "IDOR allowing credit card deletion" -- a simple insecure direct object reference bug on the credit card deletion endpoint allowed an attacker to delete, but not view, credit cards not belonging to them.
"If you are interested in helping keep Twitter safe and secure too then head on over to our bug bounty program, or apply to one of our open security positions!" he said.
Source IANS
-
99,999
-
1,29,999
-
69,999
-
41,999
-
64,999
-
99,999
-
29,999
-
63,999
-
39,999
-
1,56,900
-
79,900
-
1,39,900
-
1,29,900
-
65,900
-
1,56,900
-
1,30,990
-
76,990
-
16,499
-
30,700
-
12,999
-
11,999
-
16,026
-
14,248
-
14,466
-
26,634
-
18,800
-
62,425
-
1,15,909
-
93,635
-
75,804