
2/6/2020
What this post added
This post details improvements to Shopify's Bug Bounty program in 2019, including a 7-day bounty payout policy, an increased maximum bounty to $50,000 (with specific increases for ACE, SQLi, and Privilege Escalation), and better surfacing of information about duplicate reports. It also discusses learning from peers, improving analytics by leveraging provisioned accounts for testing frequency insights, and running experiments in a private program (Shopify-Experiments) such as expanding scope and refining response automation. Automation for incident management was improved with shorthands and emoji responses for Slack-based report handling. Statistics highlight reduced average response, triage, bounty, and resolution times, alongside an increase in disclosed bugs. Total bounties paid and average bounty awarded decreased compared to the previous year, partly due to a large payout event in 2018 and the merging of the Shopify Scripts bounty program.