Bug Bounty Program and Security Vulnerability Management
2017 Bug Bounty Year in Review - Shopify

2017 Bug Bounty Year in Review - Shopify

2/22/2018

What this post added

This post details the 2017 year in review for Shopify's Bug Bounty program. It highlights specific high-value bug reports and their technical root causes (e.g., incorrect logic in collaborator account conversion, race condition in partner auto conversions, XSS in SVG parser and storefront). It also covers participation in the H1-415 hacking event, detailing the event's structure, outcomes (bugs resolved, payouts), and the insights gained into hacker methodologies. Statistical analysis of the program's performance in 2017 is provided, including average bounty increases, total payouts, response and triage times, and the percentage of resolved vs. invalid reports. Finally, it announces program changes for 2018, including quicker payments for triaged reports, improved program clarity, and early feature access for hackers.

Read the original post ↗