Bug Bounty Program and Security Vulnerability Management
Bug Bounty Year in Review 2019 - Shopify

Bug Bounty Year in Review 2019 - Shopify

2/6/2020

What this post added

This post details improvements to Shopify's Bug Bounty program in 2019, including a 7-day bounty payout policy, an increased maximum bounty to $50,000 (with specific increases for ACE, SQLi, and Privilege Escalation), and better surfacing of information about duplicate reports. It also discusses learning from peers, improving analytics by leveraging provisioned accounts for testing frequency insights, and running experiments in a private program (Shopify-Experiments) such as expanding scope and refining response automation. Automation for incident management was improved with shorthands and emoji responses for Slack-based report handling. Statistics highlight reduced average response, triage, bounty, and resolution times, alongside an increase in disclosed bugs. Total bounties paid and average bounty awarded decreased compared to the previous year, partly due to a large payout event in 2018 and the merging of the Shopify Scripts bounty program.

Read the original post ↗