Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

LinkedIn Paid Out Over $65,000 in Private Bug Bounty Program

LinkedIn has been running a private bug bounty program through the HackerOne platform since October 2014. The business-oriented social networking service provided on Wednesday some details on the benefits of having such a program.

LinkedIn has been running a private bug bounty program through the HackerOne platform since October 2014. The business-oriented social networking service provided on Wednesday some details on the benefits of having such a program.

According to Cory Scott, LinkedIn’s director of information security, researchers reported a total of 65 “actionable” vulnerabilities since the launch of the program. The company has awarded these individuals more than $65,000 for their contribution to making the service more secure.

LinkedIn says it has received numerous vulnerability reports at its dedicated email address, security(at)linkedin.com. While many of the reports sent through this channel have not been actionable or meaningful, a small group of researchers have regularly submitted useful information. The private bug bounty program was launched for these individuals, Scott said.

“We did evaluate creating a public bug bounty program. However, based on our experience handling external bug reports and our observations of the public bug bounty ecosystem we believe the cost-to-value of these programs no longer fit the aspirational goals they originally had,” Scott explained in a blog post. “This private bug bounty program gives our strong internal application security team the ability to focus on securing the next generation of LinkedIn’s products while interacting with a small, qualified community of external researchers.”

Scott has pointed out that public programs have a poor signal-to-noise ratio due to numerous incorrect, incomplete or irrelevant reports. On the other hand, the signal-to-noise ratio of the private program is currently 7:3.

LinkedIn is encouraging users to continue submitting vulnerability reports via the security(at)linkedin.com email address, but the company’s bug bounty program remains private. The program is invitation-only; LinkedIn says it selects researchers based on their reputation and previous work.

Advertisement. Scroll to continue reading.

The number of researchers currently enrolled in the bug bounty program is not being released. Those who express interest in the program will be evaluated by the LinkedIn security team, but the company says it’s currently not accepting additional researchers into the program.

LinkedIn plans on releasing annual reports detailing the number of bugs submitted through the program and the amount of money paid out to contributing researchers.

It’s not surprising that LinkedIn wants to make sure its systems are properly secured against hacker attacks. In 2012, the company suffered a data breach in which attackers obtained 6.5 million customer records. Shortly after the incident, the social media giant announced that it had spent between $500,000 and $1 million on investigating and addressing the breach.

Related: Google Launches Android Security Rewards Program

Related: United Airlines Offers Air Miles in New Bug Bounty Program

Related: Dropbox Launches Bug Bounty Program

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.