Jump to content
Aerosol

Pinterest throws cash at topless bug-finders

Recommended Posts

Posted

823785657.jpg?x=648&y=429&crop=1

Pinterest has stopped giving out t-shirts and started paying cash for vulnerabilities found under its bug bounty program.

The web clipboard will offer up to US$200 under the BugCrowd-managed program for nine of its assets, including the Android and iOS applications.

Security engineering lead Paul Moreno said the number of bug reports increased tenfold since it launched its tee-shirt bug bounty prior to its migration to HTTPS. "Prior to the HTTPS migration, we were hesitant to open a paid bug bounty program because of a number of known vulnerabilities associated with being only HTTP," Moreno says.

"Now that a number of gaps have been closed as a result of the migration, we’re happy to announce that we’ve upgraded the program with payouts results.

"We highly encourage the whitehat hacker community to use our program and report bugs, which helps us keep Pinners safe and increase our security posture."

Top bounties will go to remote code execution, "significant" authentication bypass, cross site request forgery, and cross-site scripting.

Punters bearing HTTPOnly cookie flags and end of life browser bugs need not apply.

Pinterest ran into some problems during its lauded HTPPS migration beginning in Briton including impact to browser performance, mixed secure and insecure content warnings, and higher content delivery network costs.

Source

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...