Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Start a HackerOne bug bounty program. #549

Closed
EdOverflow opened this issue Mar 6, 2017 · 10 comments
Closed

Start a HackerOne bug bounty program. #549

EdOverflow opened this issue Mar 6, 2017 · 10 comments
Labels
defense protecting ourselves, our users and innocent third-parties

Comments

@EdOverflow
Copy link
Member

HackerOne Professional is now free for open source projects: https://www.hackerone.com/blog/HackerOne-Professional-Free-For-Open-Source-Projects

@Changaco Changaco added the defense protecting ourselves, our users and innocent third-parties label Mar 30, 2017
@EdOverflow
Copy link
Member Author

@Changaco: Would you like to go ahead and set up a VRP on Hackerone? I will help write a nice policy and triage reports.

@Changaco
Copy link
Member

Changaco commented Oct 2, 2017

I'm worried about being distracted by both noise and genuine reports. I would also prefer having fewer known issues before asking the community to help us find more.

@EdOverflow
Copy link
Member Author

@Changaco: From experience, no matter what you do, there is very little chance that you will prevent noise. I agree that some of the Self-defense tickets should be resolved before we start, but I would not worry too much about noise.

@EdOverflow
Copy link
Member Author

I forgot to clarify my terminology. We need to discuss whether you want to launch a bug bounty program (BBP) or a vulnerability disclosure program (VDP). The former would require financially rewarding researchers that report valid security issues to Liberapay. The latter is basically a security@ address on a platform such as HackerOne.

@Changaco
Copy link
Member

Changaco commented Nov 5, 2017

Using the organization's funds requires consensus among the codirectors. Want to open an issue in the org repo?

@EdOverflow
Copy link
Member Author

I am still up for managing this. Since I work for HackerOne now, I can probably get things sorted out fairly quickly. It would be nice to have an inbox that all project maintainers can keep an eye on — a platform seems ideal compared to an email inbox.

@Changaco
Copy link
Member

@EdOverflow I've created the program and invited you. I guess the next step is to figure out bounty amounts, then we should be ready to launch.

@Changaco
Copy link
Member

Changaco commented Jun 2, 2018

Done: https://hackerone.com/liberapay.

@Changaco Changaco closed this as completed Jun 2, 2018
@EdOverflow
Copy link
Member Author

Fantastic work! This is just what we needed.

@Changaco
Copy link
Member

Changaco commented Jun 7, 2018

For the record, a small illustration of the negative side of opening a program on HackerOne:

Screenshot of traffic stats from Cloudlfare

Without Cloudflare's "Under Attack" mode all those requests would have hit the origin server.

Related comments: liberapay/salon#218 (comment).

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
defense protecting ourselves, our users and innocent third-parties
Development

No branches or pull requests

2 participants