Bug Bounty Program and Security Vulnerability Management
Bug Bounty Year in Review 2018 - Shopify

Bug Bounty Year in Review 2018 - Shopify

12/20/2018

What this post added

This post details the year-in-review for Shopify's Bug Bounty program in 2018. Key technical contributions include a reduction in average time to triage from four days to 10 hours, achieved by dedicating one team member per week to HackerOne triage and implementing a tiered validation process for critical, high, medium, and low severity reports. The post also describes the technical aspects of the H1-514 live hacking event, including opening submissions early, disclosing resolved reports during the event, using innovative bonuses for specific bug types (GraphQL, race conditions), and providing shell access to infrastructure. It also presents statistics on bounty payouts, response times, triage times, and report resolution rates, highlighting improvements in efficiency and effectiveness.

Read the original post ↗