Dont Extort Us: Uber Clarifies its Bug Bounty Policy

  /     /     /  
Publicated : 22/11/2024   Category : security


Dont Extort Us: Uber Clarifies its Bug Bounty Policy


Updated parameters should help avoid future extortion incidents.



Uber this week outlined more specific guidlelines for its bug bounty program in the wake of its 2016 data breach that demonstrated gaping holes in its vulnerability disclosure policy.
The ride-sharing company last fall
revealed
that it had paid two hackers $100,000 to destroy driver and rider data they had stolen from a cloud storage location, and that it had failed to disclose the breach for a year. Since then, the company has been working on retooling its bug bounty program to encourage proper disclosure.
The
new policy states
, in part: Dont extort us. You should never illegally or in bad faith leverage the existence of a vulnerability or access to sensitive or confidential information, such as making extortionate demands or ransom requests or trying to shake us down. In other words, if you find a vulnerability, report it to us with no conditions attached.
Read more
here
.
 
 

Last News

▸ ArcSight prepares for future at user conference post HP acquisition. ◂
Discovered: 07/01/2025
Category: security

▸ Samsung Epic 4G: First To Use Media Hub ◂
Discovered: 07/01/2025
Category: security

▸ Many third-party software fails security tests ◂
Discovered: 07/01/2025
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Dont Extort Us: Uber Clarifies its Bug Bounty Policy