The HackerOne platform enables security researchers to inform companies and software developers about identified vulnerabilities and receive rewards for doing so. It has announced the inclusion of open-source software in the Internet Bug Bounty project. Bounties can now be awarded not only for vulnerabilities found in corporate systems and services but also for reporting issues in a wide range of open projects developed by both teams and individual developers.
Among the first open projects eligible for bounty payments for discovered vulnerabilities are Nginx, Ruby, RubyGems, Electron, OpenSSL, Node.js, Django, and Curl. The list will be expanded over time. For critical vulnerabilities, a payout of $5000 is provided, for high-risk — $2500, for medium — $1500, and for low — $300. The bounty for a discovered vulnerability is distributed in the ratio of 80% to the researcher reporting the vulnerability and 20% to the maintainer of the open project who added the fix.
Funds for the new program are pooled separately. Major sponsors of the initiative include Facebook, GitHub, Elastic, Figma, TikTok, and Shopify, while HackerOne users are given the option to contribute between 1% and 10% of their allocated funds to the pool.
Source: opennet.ru
