Skip to content
AppSec PodcastThe Application Security Podcast — home
36 min

Adam Bacchus and Jon Bottarini -- Two Sides to a Bug Bounty: The Researcher and The Program

With Adam Bacchus and Jon Bottarini

Building an AppSec ProgramVulnerabilities and ExploitsCareers in AppSec

What does a bug bounty look like from both sides of the relationship? Adam Bacchus and Jon Bottarini of HackerOne compare the responsibilities of the program operator with the experience of the security researcher.

Listen

Audio hosted by Buzzsprout. Nothing loads until you press play.

Episode chapters · 17 chapters
  1. 00:00Two sides of a bug bountyAudio
  2. 02:33A researcher’s security origin storyAudio
  3. 06:34The size and scope of bounty programsAudio
  4. 08:00Safe harbor for security researchersAudio
  5. 09:17Where bug bounties fit in AppSecAudio

About this episode

What does a bug bounty look like from both sides of the relationship? Adam Bacchus and Jon Bottarini of HackerOne compare the responsibilities of the program operator with the experience of the security researcher. They discuss safe-harbor language, where bounty programs fit alongside scanners and penetration tests, and why business-logic flaws still depend on human creativity. Adam explains response metrics, payout structures, public and private programs, and the maturity an organization needs before inviting researchers. Jon describes researcher profiles, reputation, learning paths, and the realities of earning money through vulnerability discovery. The conversation gives organizations a clearer picture of the operational commitment behind a bounty and gives aspiring researchers practical ways to begin building skill and credibility.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Adam Bacchus and Jon Bottarini:
Adam Bacchus on LinkedIn
Jon Bottarini on LinkedIn
HackerOne

Resources
HackerOne
Hacker101
HackerOne Hacker Report

Actionable

From this conversation

  1. Start a private bounty program

    We have some organizations that are dipping their toes into working with the external hacking community And they'll start their program in what's called private mode.

    7:01
  2. Analyze root causes of bounty findings

    In additional to— or excuse me, in addition to the tactical benefit of finding and squashing those individual bugs, you can perform some root cause analysis of the bugs flowing through your program and identify and implement systematic improvements to your overall security posture.

    10:02
  3. Practice on Hacker101

    If you want to learn how to perform a cross-site scripting attack, Going through the training modules on that site will give you all the information that you need to know, and then you can take that information and apply it to the different types of bug bounties on the platform.

    23:26
Transcript · 36 min conversation

0:00Chris RomeoHey folks, season 4, episode 15 of the AppSec Podcast. On this episode, we're joined by a couple of folks from HackerOne to talk bug bounty. So Adam from HackerOne is coming at bug bounty from a program perspective, and John's coming at it from the security researcher perspective. And so they both have a lot of insight to share with us about how you put these 2 pieces together inside of an AppSec program to truly be successful with bug bounty. So we hope you enjoy. The Application Security Podcast. Here we go. Hey folks, welcome to this episode of the Application Security Podcast. On this episode, we're going to talk about bug bounties, and we're actually joined by a couple of individuals from HackerOne, Adam and John. And so just like every other episode, we're at roughly 70 at this point, we always begin with a security origin story, and in this case, we're going to get to hear 2 of them. So Adam, why don't you go ahead and go first and introduce yourself for our audience and tell us, how did you get into security?

1:27Yeah, absolutely. Hi everyone, my name is Adam Bacchus. I'm HackerOne's Director of Program Operations. So my security origin story, I got a BS in computer science from the University of Minnesota. Mostly what I learned there was programming, software development, not too much in the security realm, but my first job out of school was as a security consultant. So it was pretty awesome. I got paid to essentially be a good guy hacker and hack on banks, hospitals, colleges, and so on, find vulnerabilities, and let them know about it. I actually found a bug in one of Google's acquisitions and reported it to them. And through that, even though their bug bounty program had not started yet, I unfortunately did not get a bounty for that bug. I got to meet their security team, and one of them referred me. So I got my foot in the door at Google. I worked there for about 4 years on vulnerability management, helping run the internal pen testing program, as well as helping run their bug bounty program.

2:23Wow.

2:23After that, I went to Snapchat down in LA for about a year, helped run their Bug Bounty program and build out their internal security team. And after that, I made my way over to HackerOne, which is where I'm at today.

2:33Chris RomeoOh, very cool. Very cool. So John, how— what's your security origin story?

2:37Yeah, first off, hi everybody. Uh, and in advance, if you hear background noise, it's because I'm at a WeWork in Argentina. We're having a live hacking event down here.

2:48Chris RomeoOh, very cool.

2:49Yeah, my, my hacker origin story is pretty similar to Adam's. I graduated from the University of Arizona with a degree in information science and technology, and since then I had nothing to do with security. So I didn't study security in school. My first job had nothing really to do with security, but the first job that I had out of college was a program manager for a group of websites that were kind of like a military defense company.

3:18Okay.

3:18So my job was to essentially make sure that these websites didn't get hacked, and they kept getting hacked over and over and over again. So coming from a realm where I didn't really have much security experience, it was really difficult for me to do my job effectively because these sites were so vulnerable. So I started really on just trying to learn the different types of vulnerabilities and what we were susceptible to. And then slowly I started trying to learn and teach myself how to do bug bounties themselves, because I figured, hey, if the hackers are getting into the sites that I control, I can probably learn how they're doing it and not only protect myself, but get into the different websites that other people control for, for a bug bounty. And that's kind of what led me to HackerOne. So I submitted my first bug to a finance company on HackerOne. I got $100.

4:09Wow.

4:10And ever since then, I was just kind of hooked. I joined HackerOne part-time as a security analyst, which was triaging the incoming vulnerabilities. And then after that, I moved to a technical program manager role. And then finally, I was promoted just a few months ago to a technical program manager 2 role and been here ever since.

4:29Chris RomeoVery, very cool. And so you're in Argentina at this moment. So is this like a hackathon-style event that you're doing to try to—

4:37Yeah.

4:37Chris Romeoand get people excited about bug bounties and stuff?

4:40It's really similar to that. It's actually really cool. What we do is we host these events all over the world. So we had one in Amsterdam, we had one in London, uh, we're having a few coming up later in different countries too. But what we do is we invite hackers from all over the world, some of our best hackers on the platform, to come together and hack on a single target. somewhere in the world where they're all in a centralized location. And it's really similar to a hackathon, but it's for real. So they're hacking a live target, they're finding real vulnerabilities, and they get paid right at the event itself. So this one here just so happens to be in Argentina, and it's tomorrow when it actually kicks off.

5:22Chris RomeoOh, very cool, very cool. So that's a— that's actually a great segue in here to the kind of the basic idea of what is this idea of a bug bounty. You know, you kind of already told us a little bit about it, but let me go back. Let me have Adam give me kind of your perspective. I think that felt like that was John's perspective there, which was good, but Adam, go ahead and kind of fill in some of the details around the edges about what is this bug bounty thing.

5:47Yeah, absolutely. So a bug bounty program is really a way for organizations to incentivize and reward security research from the hacking community, usually on their externally facing assets. So As an example, if I'm a hacker out there, I can go to hackerone.com/snapchat, and on that URL you'll see a page that'll tell me what's in scope, what's out of scope in terms of assets and vulnerability types. Basically, what are the rules of engagement? From there, I can hack away. If I find a bug, I can submit it to Snapchat via the HackerOne platform. Their team will review the bug and say, oh yep, that's legitimate. And they can decide based on the severity or impact of that issue, how much of a bounty or monetary reward is appropriate for it, and then pay me out via the HackerOne platform.

6:34Chris RomeoOkay. And so, you know, I think of Snapchat, I think of a big tech company, not a big tech company, but I guess a tech company with a lot of users, a very active kind of platform there. Is that a typical size and scope of an engagement that people can do when they're, they're trying to set up a bug bounty themselves? Or are there different— is there like a small, medium, and large? Is there a supersize option? What, what are my options there?

7:01Yeah, absolutely. So what's really cool about bug bounty programs, and a distinction we should probably make here as well, is bug bounty versus vulnerability disclosure, okay, um, is that they can fit any size, you know, it's tiny, medium, huge. We have some organizations that are just dipping their toes into working with the external hacking community And they'll start their program in what's called private mode. So they won't publicly state they have a program, but they'll invite, you know, maybe 5 hackers or so to take a crack and see what they can find, and they'll slowly ramp it up from there. Getting back to the disclosure versus bug bounty difference. So for disclosure programs, basically you're putting out a policy page that says, hey, we'd love to work with the external hacking community. Please, you know, take a look, see what you can find. Here are rules of engagement. We promise we're not gonna try to sell you or throw you in jail or do anything crazy like that. This is a safe place for you to hack and let us know about it. And the difference with the bug bounty program is primarily that there's money involved and you can actually get paid out for those bugs.

8:00Chris RomeoAnd I guess there's a— so when a company actually sets up a bug bounty, they are giving— so the researcher almost has a little bit more protection from the bug bounty program in that the company has set up this program, there's got to be a legal document that's somewhere behind it that drives kind of what, you know, what are the rights and responsibilities and, you know, how are, you know, so that's basically saying that someone's not going to get sued if they do, you know, work with that program. So is that a difference kind of that you see or that people are concerned about from the vuln disclosure to bug bounties?

8:38Yeah, so in both cases, researchers are protected. And one thing we're trying to push across the platform is what's called safe harbor language. So more and more we're seeing organizations embed the Safe Harbor language into their program page or their program policy or their rules of engagement that essentially says, hey, you know what, if you abide by the rules of the program, if you don't try to DDoS us, you know, if you don't try to steal other users' data, you try to basically play by the rules and play it safe, we assure you that we're not going to pursue legal action.

9:07Chris RomeoOkay, yeah, that's a good, that's a good thing. Nobody wants to have— be on the run in, you know, some other country.

9:15Yeah.

9:17Chris RomeoYeah. So, um, so let's talk about bug bounty in the traditional application security program, because, uh, you know, I see a lot of, um, I see a lot of people that have— they kind of jumped on the bug bounty train, and it was a little early. You know, they, they, they didn't have everything kind of figured out behind the scenes that they should have. And so they, they thought bug bounty was cool and they jumped in and then they ended up paying out bounties for things that they should have found with a vulnerability scanner themselves. So, you know, kind of, I guess, Adam, gimme your take and then John, we'll come back to you kind of from the, I guess, the researcher perspective. But how does, you know, as someone who's responsible for program, how does the bug bounty fit into the traditional AppSec program?

10:02Yeah, absolutely. So any bug identified via a bug bounty or vulnerability disclosure program, as you mentioned, will highlight areas of improvement within your existing security program. So in additional to— or excuse me, in addition to the tactical benefit of finding and squashing those individual bugs, you can perform some root cause analysis of the bugs flowing through your program and basically identify and implement systematic improvements to your overall security posture. I would say that, you know, bug bounty programs really help augment your existing security processes and kind of act like a neighborhood watch or safety net to catch any vulnerabilities that fall through the cracks. But as you mentioned, it's very important to perform your due diligence first. You don't want to start too big. Like we mentioned, a lot of programs will start smaller, they'll start private, invite a few hackers to get their processes in place. It's a new source of bugs. It's a new source of bugs coming at you. And so if you don't already have good vulnerability management processes or the resources in place to actually field these bugs and work on them, you won't get quite as much value. Bugs are really, you know, security only improves when bugs are fixed, not when they're found.

11:09Chris RomeoYeah, so John, do you think you could walk us through kind of an example of what Adam was talking about here as far as how the bug bounty— take us through an example of something that would be found and kind of walk it back through into the AppSec program.

11:26Sure. Yeah. So a really great example that I have is when you run a traditional security scanner on a website, it usually picks up the pretty obvious, right? Like the CSRF, the cross-site scripting issues. Any standard scanner can probably pick on that really well. But when you bring in the human element, and that's really what you're getting with a bug bounty program, you're able to really dig down into the application business logic itself. And what I mean by this is that you're able to pick up as a hacker on different types of vulnerabilities that really a scanner wouldn't be able to understand and wouldn't be able to find itself. Perfect example of that. There was a bug that I found about a year and a half ago which basically enabled me to buy something for free. So a security scanner, when it runs through this option, it says, okay, is there a SQL injection here?

12:19No.

12:19Okay, on to the next test. Is there cross-site scripting here? No. Okay, on to the next test. But the ability to really combine different types of vulnerabilities together and chain them in a way where it actually affects the core business that you're, that you're targeting, it really provides some impact to the organization that otherwise wouldn't be able just to click a button and get that vulnerability delivered.

12:39Chris RomeoYeah, that, that makes sense. So, um, yeah, so, so the business logic type of problems are things that the scanners just can't do Until somebody comes up with some artificial intelligence where the robots can take over the world, you still need human beings, right?

12:56Exactly.

12:57Chris RomeoTo go out and think about the business logic because you just can't script logical flow and following a path through the system. So, Adam, you mentioned the program side of this. And so, John kind of gave us the perspective of, you know, a particular issue and kind of walked us to the issue itself. Adam, how do you walk that issue back and take it back into the AppSec program? And 'cause I'm thinking about like when somebody has one of these bug bounties going, somebody finds this problem, then what do they do to improve? And it's more than fixing the bug. Obviously they're gonna fix that single problem, but how do they get better by taking the things that come outta the bug bounty and actually make programmatic improvements? And what do they improve?

13:40Yeah, absolutely. So it's important with any of these bugs to go back and do root cause analysis and try to figure out how did this bug actually get introduced? Is it a developer education thing? Is it that we're not using particular libraries that would help prevent these from the first place? So really digging in and figuring out what the root cause is of that individual issue and tracing it back to its source. Beyond that, beyond just individual bugs, what I see a lot of organizations do with their program is they trend this data over time. So for example, they might notice, hey, this one particular asset has way more vulnerabilities of this particular type than any other assets in our portfolio, and we know that this asset is mostly built and maintained by this one team. They go talk to that team and they realize, oh, okay, this team just needs a little bit of education, or they just need to invest a little bit more in proactive security measures as they're building their code out. So those are some of the ways that people will take the data from their program and systematically improve their existing security program.

14:39Chris RomeoOkay. Yeah, so the—

14:43that—

14:43Chris Romeoso that kind of gets you— you're kind of touching on, I guess, some of the metrics and things there. So what are the— I guess, what are the metrics other than kind of that trend? I mean, trend data, it sounds to me like you're talking about from a perspective of just incident, you know, issues found and where they're found across the things that are included in the bug bounty. What other metrics other than the detection or the finding of vulnerabilities can folks be looking at?

15:10Yeah, absolutely. So in addition to the number and types of bugs they're receiving, people want to look at the criticality of those bugs. You know, if I start a bug bounty program and all I'm getting is low-hanging fruit and things that could be caught by automatic scanners, it's not quite as valuable. What most organizations do is if the well is kind of running dry, they're not really getting a lot of interesting bugs, they'll use this as a cue to up the ante So Intel, for example, they offer a max bounty of, I think it's $250,000, which is pretty, pretty epic, right?

15:42Mm-hmm.

15:42And the reason they can do this is that they've hardened their attack surface over time, and they realize that the level of effort and skill required to find a big, juicy, critical bug warrants the additional potential payout. Beyond those sorts of metrics, other things that a program will wanna look at to see if they're successful is having solid response times make sure hackers are kept up to date, as well as having good polished vulnerability management processes. So what's their time to remediation? What's their time to response on these vulnerabilities that are coming through? And then engaging with the community in creative ways, like John was mentioning, these live hacking events. These are all signs of a mature program.

16:17Chris RomeoYeah, and that's, I guess, from the metrics. So basically the metrics are all focused on the vulnerabilities themselves. And there's nothing, there's nothing outside of that category of kind of, I guess, metadata about the vulnerabilities that are, that's interesting to track?

16:35Yeah, so the number of bugs, the types of bugs, where they're located, what are the trends across where they're located, how long is it taking you to fix those bugs, and then as I mentioned before, the responsiveness. So John might be able to comment on that as well in terms of the importance of a program being responsive. Right.

16:54Yeah, I just wanted to add to that too. When you're talking about metrics, we've had companies and programs in the past where they've released certain assets in scope and then they've removed them in scope, and then they'll add another type of organization's assets in scope. And since they have a lot of assets to add all at once, they're trying to gauge which one of their subsidiaries or which one of their child companies is most secure. And why is that? And how can they borrow— sorry, I got loud there— how can they borrow the security of one organization and apply it to another? So when it comes to metrics, the reports submitted to each one of these different child programs is really, really critical. It really goes a long way to take it back inside the organization and drive organizational change.

17:40Chris RomeoSo they're really looking, they're searching for best practices then in that case study that you're talking about where—

17:45Exactly.

17:45Chris RomeoThey're looking to say, okay, we've got all these other companies, Let's see who's the best, and then let's try and mimic what they're doing and push their best practices across the rest of the organization.

17:57Exactly.

17:58Yeah, let's figure out why.

17:59Chris RomeoAfter the break, Adam explains the different metrics for a company just starting versus a more mature company. The Application Security Podcast operates with support from Security Journey. A Security Belt Program provides the 3 pillars of successful AppSec training: learning, application, and experience. Visit us on the web at www.securityjourney.com to learn how you can teach and empower your developers using a new kind of security training. Adam dives back in with some different metrics based on a company's maturity level.

18:43Yeah, so for a company that's just starting out, usually if they're brand new to this, things like responsiveness are gonna be very important. You're really giving a first impression to the hacking community when you launch a new program. So are you paying market value for bounties, right? Are you quick in responding and paying out? And are you quick to resolve? So these metrics are pretty important to really set a good tone with the community.

19:08Chris RomeoAnd what do those actually look like? I mean, what are those like responsiveness? What is somebody who's starting out what should they be aiming for here? Is it like 24 hours, some type of response, or, you know, what's a good perspective?

19:21Yeah, absolutely. So in some cases, organizations will actually purchase triage services from HackerOne, and for that, we usually try to get back to hackers within a day or 2, depending on the level of the contract in terms of this is a valid issue or not. When it comes to payouts, you know, usually If they can do it within a couple of weeks, that's usually pretty solid. It depends on the organization, right? So some organizations, the security team member running the program has a lot of wherewithal and they can just pay out as they please. They have that power control. Other organizations, they might have some sort of approval process, right? Like it's gotta go to a panel, 5 people gotta give it the thumbs up, and then they can pay out the bounties. That could take a week or 2.

20:02Chris RomeoOkay, now, would you see starters— yeah, sorry, do you see starting companies have like a lower, you know, like, is it— doesn't— so you said a more mature company like Intel is going to have a $250K kind of bounty. And then so what is a starter company? What's going to be their kind of range for those in the beginning when they're kicking off?

20:20Yeah, it depends on a lot of factors, right? So what is their budget? What is their current level of security maturity? If they've got a big budget and they already have a pretty solid security program in place, they can afford to start off a little higher. If they're more towards the beginning of their journey, you don't want to break the bank right away if you get drowned in bugs. So for a company starting out, I'll let John chime in on this as well, but a critical bug on the low end, maybe like $1,000 for a critical bug. On the upper end, just starting out, maybe like $5,000 for a critical bug.

20:53And then you have to realize too, as a hacker myself, I'm going to prioritize my time, right? So if I see a program on board and I see, okay, this seems to be a pretty large scope, their response times to hackers are really good, I'd probably go with them even if they're only offering $1,000 for a critical severity issue compared to a program that is really bad at responding to hackers, takes a long time to issue bounties, but may have a higher maximum critical bounty. So for me as a hacker, I care a lot about responsiveness. And I really care about, you know, what program is going to take care of me after I've delivered the bug.

21:34Chris RomeoActually, I have a question about the profile you mentioned about the hacker. What kind of hacker? I'm curious about the kind of profile that you might see, you know, the bug hunter, the security researcher or hacker. You know, what's the typical profile for them?

21:50Yeah, so that's a great question. It's pretty important to find out and kind of know a little bit about who's going to be poking at your assets. And what HackerOne does every year is we have this report that we make, and it's called the Hacker Report. And we poll every single person. It's a survey that goes out. So every single person on our platform receives this survey. And what we ask during the survey is where they're from, their background. And we have some really interesting statistics that come from this report every single year. In the 2018 Hacker Report, we found that over 90% of the hackers on the platform platform are under the age of 35, and roughly 50 to 60% are self-taught when it comes to security. So you have a really big number of people who are learning security by themselves, who are self-taught. And I think within the survey itself, it was roughly 40 to 45% come from an IT background. That's, that's the typical makeup of a hacker. And it's interesting for me to read the Hacker Report because It's, it's, I don't know what to make of this data, but I almost fit into every single one of the majorities. So I'm still not really sure what to take away from that. I guess if you were to plaster someone on a billboard, it would be either a picture of me or someone from, from that type of, that type of background.

23:10Chris RomeoOkay, so taking that in consideration, what would you recommend for somebody who wants to get started? You know, you have a profile, but How would you tell someone, hey, here's something to consider in terms of something to look out for?

23:26Yeah, I get this question all the time. The best way to get started is to really just to go to HackerOne. We have this resource that teaches you some of the more common types of vulnerabilities. It's hacker101.com. And the great thing about this site is that it's interactive. So if you want to learn how to perform a cross-site scripting attack, Going through the training modules on that site will give you all the information that you need to know, and then you can take that information and apply it to the different types of bug bounties on the platform. That's really how I got started. I also got started by reading write-ups from the Hacktivity feed, and the Hacktivity feed, it's a page on HackerOne which lists all of the disclosed public vulnerabilities from other researchers on the platform. So if you're a researcher or a hacker trying to get started with bug bounties, you can go to this page and basically learn from the best. All of, all of the disclosed reports there are going to be pretty high quality and walk you through the entire process and working with the program.

24:27Chris RomeoSee, I think that's a good, good description of kind of the people. And I think it is interesting that 90% of them are under the age of 35. But I think that tracks with the fact that they're self-taught. And so these aren't people that are doing kind of university degrees or anything like that. So any other correlations on the statistics that come out of that? Like, do these people have certifications or any type of credentials, or are they literally self-taught and just, you know, that they're just kind of stating what they can do versus being recognized in any way?

25:07I don't think we polled the community on their certifications. I can say just based by myself, I don't have any certifications personally. The people that I work with that are also hackers, very few of them actually have a certification. Adam, I'm not sure, do you have a certification yourself or do you know internally what the number of certifications are?

25:30Yeah, I can, I can chime in on that. I also do not have any certifications and I know there's varied opinions on that. I would say that with our community. Some have certs, some don't. But I think what's really amazing about bug bounty programs is that it's really a truly democratizing and equalizing concept, right? You could be 15, you could be 50, from any part of the world, it really doesn't matter. At the end of the day, if you found a bug, you found a bug, you know, plain and simple. Hackers benefit, they get bounties, and organizations benefit by paying for results. So at the end of the day, it's great to have hackers that have credentials. Sometimes they do, sometimes they don't. But ultimately, on both sides of the equation, you're really benefiting by getting true bugs, and that pretty much speaks for itself.

26:14Chris RomeoSo does your platform have any type of rating system? So if I'm a big vendor and I want to do something privately and I don't necessarily want to make it available to everyone in the world to test, can I target some group of people and invite them based on some type of criteria?

26:33Yeah, absolutely. We actually have an offering called Clear. And so for some organizations that want to work specifically with hackers that are background checked, and so on and so forth, we do have those smaller, smaller programs, those smaller concepts where you can work with a specific subset of people, all the way up to having a huge public program where anybody in the world can submit.

26:54Chris RomeoOkay, so what's the biggest bounty that's been paid out? on the HackerOne platform to date, or is it something that it's classified and I don't— if you, if you told me, I'd have to disappear?

27:08It's a good question. John, do you know off the top of your head what our biggest one is right now?

27:13You know, Snapchat has to be up there. Uh, it was either, I think, $15,000 or $20,000. Don't, don't quote me on that, but Snapchat had a really, really big one recently. Um, Off the top of my head, I know that there are private programs that have larger payouts. But for the sake of being private, I won't be able to say their name specifically.

27:34Chris RomeoOf course. Yeah. Yep. Yeah. So Snapchat, $15,000 to $20,000, somewhere in that range. So actually, sorry.

27:42Oh, sorry. Sorry to interrupt. I think we actually had a $100,000 payout from Intel as well. I think that was—

27:50yep. I forgot about that one.

27:53Yeah.

27:54Chris RomeoSo what is it? So going back to the researcher side now, now I'm curious about the life of a security researcher. John, I'm guessing you know a lot of these folks now that use the HackerOne platform. What is, I mean, do you know what a typical day looks like in the life of a security researcher that uses the HackerOne platform?

28:14I do. Yeah. I can tell you my typical day back when I was doing bug bounty almost full-time. And then I can kind of compare it to other people on the platform that are also doing this.

28:26Chris RomeoOkay.

28:27So when I was, when I was doing bug bounty, I say, I say full-time, but I'll tell you what I mean by that. I was working at my, my first job out of college, and I was doing bug bounty when I got home. So I would go to work at 9 AM, I would leave at 5, 5:30 I would get home, and I would really just, I would hack well into the night. way, way longer than I should have been. And this process repeated for a couple months until I realized that— and it's just the, the reality of it was that I was making more money doing bug bounty than I was going to my 9-to-5 job. So for me, that was what really— it was the tipping point for me that made me realize, hey, there's, there's something here. There's something that I really need to capitalize on. The other researchers that I know personally and that I work with really closely. A lot of them, because they are a little bit younger, they're going through school. So we have one of the researchers on the platform who did really, really well in one of the Hack the Pentagon events, which is an initiative that we do bug bounties through the Department of Defense. And he made so much in one of these Department of Defense bug bounties that he paid his way through college.

29:38Wow.

29:39So that's— it's a really incredible and empowering ability to not only have this way to increase your income and to pay for your expenses, but really to change your future and outlook when it comes to that.

29:51Chris RomeoYeah. And I'm guessing you have people from all over the world that are part of this community. And so, you got people from other locations where the cost of living isn't as high as it is like in San Francisco or something.

30:06That's exactly right. A $1,000 bounty here in the United States, it's, it's great, right? But it's, it's not life-changing. A $1,000 bounty in a third-world country where the annual income is somewhere around $100 to $200, I mean, that's, that's truly life-changing. And we've seen it time and time again that in addition to, you know, helping themselves go to college or buying different items, they're really helping their families at that point. Yes, we had a hacker. Oh, sorry, go ahead.

30:39Chris RomeoNo, no, please tell me the story. What, uh, I love personal stories.

30:42Yeah, we, we had a hacker who, you know, his family, uh, wasn't that well off and he was in a third world country. And through the way that he was doing the bug bounties and the income he received, he was really able to buy a house for not only himself but his family and really increase their standard of living. So that, I mean, that's just one of the many, many success stories that I've seen just just in the bug bounty community itself.

31:07Chris RomeoYeah, you must, you gotta, you must have a fun job here, given that you get to interact with this community. And I love it, kind of know what, what makes them tick. So what's, what is the average security researcher that's, that's participating in bug bounties? What are they making, would you say, on average? And I don't need to know an exact, you know, exact average, just give me a range. Like, what are these folks pulling down per month?

31:32You know, it really comes back to what their involvement is. Bug bounty isn't a full-time gig for most, and those who are making it full-time, they can easily make well over $100,000 a year if you're doing it full-time. For the part-time folks, it's going to be considerably less, and it's really going to come down to your experience and also the amount of time that you're dedicating towards it. I, I know people who are making, uh, $10,000 a year and all the way up to $50,000 a year just doing it part-time. And then if you're full-time bug bounty and you're doing that as your sole source of income, easily I've seen people go $100,000 and above.

32:13Chris RomeoNow, are those people working 40 hours a week, or is this something that's like an all-encompassing type of pursuit?

32:19I would have to ask them. I'm not entirely sure. I I'm really interested though. Yeah, go ahead, Adam.

32:26Oh, sorry. Yeah, sorry to interrupt. I've got some stats actually, if that's interesting.

32:30Chris RomeoYeah, definitely. I'm interested.

32:32Yeah, absolutely. So from our 2018 hacker report, about 20% of hackers hack 30+ hours per week. Over 3% are making more than $100K per year. 1.1% are making over $350,000 annually. I'd like to be one of those hackers. A quarter of hackers rely on bounties for at least 50% of their annual income, and 13.7% say that their bounties earned actually represent 90 to 100% of their annual income.

33:00Chris RomeoWow. I think one of the things that I learned in this conversation is that if somebody's thinking at all about doing a bug bounty, they should probably go read this hacker report. And because I've heard a number of very interesting things, and I'm going to actually go read it myself. Even though I saw it pass by when y'all released it, but I didn't go and read it, but now I'm intrigued and I want to know more. So very cool. So you talked about Hacker 101 as a place that people can go to get started if they wanna be a researcher. What are your recommendations for somebody who is perhaps responsible for a small, maybe medium, maybe even large application security program, which is a good chunk of our listeners, and they want to get started in this idea of bug bounty, where's the place that they can go to get some more information or to kind of get, um, and not even necessarily kind of like from a sales perspective, but just in the general kind of knowledge perspective, what are some sources they can go to to kind of help them other than this podcast?

34:01Yeah, absolutely. Um, this is a little self-serving, but, uh, I wrote this asset called the Bug Bounty Field Manual. And it's huge. I think it's like 70+ pages. It's kind of a beast, but highly recommend the Bug Bounty Field Manual. Uh, it gives a lot of advice on how to initiate, plan, launch, and run a bug bounty program from beginning to end.

34:20Yeah.

34:21So that's one asset. Um, there's a webinar version as well on YouTube, the 40-minute, you know, Reader's Digest version if you prefer video content. Um, beyond that, uh, honestly, I just recommend following folks in the community. The same thing that John mentioned for hackers, it applies to folks running programs. Uh, try to find those people in the community that are running really successful programs. Find them on Twitter, find their blogs, find their write-ups on Medium. There's a lot of great community-generated content on both sides of the fence. Okay.

34:47Chris RomeoYeah. And that— and so where can folks find the Bug Bounty Field Manual? Where is that? Is that like on Amazon, or is it something that's for download, or where, where's it at?

34:55Yep, uh, you can download it for free from HackerOne. If you just Google for Bug Bounty Field Manual, it'll be one of the first few results on HackerOne's website.

35:03Chris RomeoVery cool. Yeah, I just found it. 70-page book.

35:06Yeah, there it is.

35:06All right.

35:07I'm sorry.

35:09That's huge.

35:10I tried to keep it light though. Should be an easy read.

35:12Chris RomeoFilled with— I'm sure filled with very good knowledge based on your experience. So that's always exciting for our listeners to be able to go and get into something that has some kind of meat to it about how to actually do the things that we're talking about. So Adam and John, thank you so much for taking the time to be with us here and for imparting all this wisdom about bug bounties. We certainly appreciate it, and we look forward to speaking to you again in the future.

35:38Thanks for having us.

35:40Yeah, thanks so much.

35:41Thanks for listening to the Application Security Podcast. If you enjoy the podcast, please do us a favor and visit the iTunes Store and give us a 5-star rating. Our intro music is 8-Bit Kung Fu by Born and TJ, and the outro A Southern Delight by Stefan Cartenberg. You can find us on Twitter @AppSecPodcast or on the web at www.appsecpodcast.org.

6,727 words · transcript by assemblyai

More like this

View all episodes →

Get Reasonable AppSec: new episodes and useful picks from the archive.