-
-
Notifications
You must be signed in to change notification settings - Fork 217
New issue
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
Start a HackerOne bug bounty program. #549
Comments
I'm worried about being distracted by both noise and genuine reports. I would also prefer having fewer known issues before asking the community to help us find more. |
@Changaco: From experience, no matter what you do, there is very little chance that you will prevent noise. I agree that some of the |
I forgot to clarify my terminology. We need to discuss whether you want to launch a bug bounty program (BBP) or a vulnerability disclosure program (VDP). The former would require financially rewarding researchers that report valid security issues to Liberapay. The latter is basically a security@ address on a platform such as HackerOne. |
Using the organization's funds requires consensus among the codirectors. Want to open an issue in the org repo? |
I am still up for managing this. Since I work for HackerOne now, I can probably get things sorted out fairly quickly. It would be nice to have an inbox that all project maintainers can keep an eye on — a platform seems ideal compared to an email inbox. |
@EdOverflow I've created the program and invited you. I guess the next step is to figure out bounty amounts, then we should be ready to launch. |
Fantastic work! This is just what we needed. |
For the record, a small illustration of the negative side of opening a program on HackerOne: Without Cloudflare's "Under Attack" mode all those requests would have hit the origin server. Related comments: liberapay/salon#218 (comment). |
HackerOne Professional is now free for open source projects: https://www.hackerone.com/blog/HackerOne-Professional-Free-For-Open-Source-Projects
The text was updated successfully, but these errors were encountered: