Bitcoin Forum
April 19, 2024, 11:45:38 PM *
News: Latest Bitcoin Core release: 26.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Coinbase Offers $50,000 Hack the World Bug Bounty  (Read 280 times)
BADecker (OP)
Legendary
*
Offline Offline

Activity: 3766
Merit: 1365


View Profile
October 28, 2017, 09:02:35 AM
 #1

Coinbase Offers $50,000 Hack the World Bug Bounty





"Coinbase Loves Bug Bounties"

Bug bounties are an increasingly used initiative by businesses to find code issues and security problems through incentivized hacking. Bounty payouts reward hackers to expose companies to problems before potential bad-actors might.

Head of Security for Coinbase, Philip Martin, blogged, "We're thankful to all the security researchers who have worked hard to find and report vulnerabilities."

Instead of researchers "facing a choice between using a vulnerability themselves," he urged, "selling a vulnerability to 3rd parties or giving a vulnerability away for free, bounties present a good, legal, risk-adjusted return for the time invested by a researcher."

To date, Coinbase has disclosed 73 discovered vulnerabilities.

Mr. Martin emphasized bounties "de-criminalize the actions of good-faith security researchers, while still forbidding malicious hacking."



Though most proposals are not relevant, Coinbase finds value in bug bounties.

Over five years, the exchange has "paid out $176,031 in bounties to 223 researchers across 346 valid reports out of a total of 3101 reports submitted," Mr. Martin noted.

This year, Coinbase joins a competition hosted by Hackerone, Hack the World. An unsigned blog post stated the venture's goals as "to help build stronger relationships between our hackers and our customers, reward high signal and high impact reports, and to have some fun along the way by giving out some awesome prizes to our top hackers."

Sponsors range from Uber, Github, and Airbnb, to Mapbox and Dropbox.

Coinbase is offering "the top 3 most impactful bugs submitted, as part of Hack The World, an additional $10,000, $7,500 and $5,000," he explained. "'Most Impactful' will be judged by the Coinbase security team on a combination of bug severity, system criticality and report quality."


Read more at https://news.bitcoin.com/coinbase-offers-50000-hack-the-world-bug-bounty/.


Cool

BUDESONIDE essentially cures Covid symptoms in one day to one week >>> https://budesonideworks.com/.
Hydroxychloroquine is being used against Covid with great success >>> https://altcensored.com/watch?v=otRN0X6F81c.
Masks are stupid. Watch the first 5 minutes >>> https://www.bitchute.com/video/rlWESmrijl8Q/.
Don't be afraid to donate Bitcoin. Thank you. >>> 1JDJotyxZLFF8akGCxHeqMkD4YrrTmEAwz
1713570338
Hero Member
*
Offline Offline

Posts: 1713570338

View Profile Personal Message (Offline)

Ignore
1713570338
Reply with quote  #2

1713570338
Report to moderator
1713570338
Hero Member
*
Offline Offline

Posts: 1713570338

View Profile Personal Message (Offline)

Ignore
1713570338
Reply with quote  #2

1713570338
Report to moderator
"Your bitcoin is secured in a way that is physically impossible for others to access, no matter for what reason, no matter how good the excuse, no matter a majority of miners, no matter what." -- Greg Maxwell
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
Fortify
Legendary
*
Offline Offline

Activity: 2646
Merit: 1172



View Profile
October 28, 2017, 09:15:53 AM
 #2

It's good in a way, it shows they are being a bit proactive in protecting their website. However any hacker who could find exploits within coinbase could earn a heck of a lot more by draining all the bitcoin wallets stored there - depending on the severity of the hack found. It is more than a lot of exchanges out there are willing to do

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
|
██░░░░░░░░░░░░░░░░░░░░░░██
▀█▄░▄▄░░░░░░░░░░░░▄▄░▄█▀
▄▄███░░░░░░░░░░░░░░███▄▄
▀░▀▄▀▄░░░░░▄▄░░░░░▄▀▄▀░▀
▄▄▄▄▄▀▀▄▄▀▀▄▄▄▄▄
█░▄▄▄██████▄▄▄░█
█░▀▀████████▀▀░█
█░█▀▄▄▄▄▄▄▄▄██░█
█░█▀████████░█
█░█░██████░█
▀▄▀▄███▀▄▀
▄▀▄
▀▄▄▄▄▀▄▀▄
██▀░░░░░░░░▀██
||.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▄██████▀████░███▄██▄
███░████████▀██░████░███
███░████░█▄████▀░████░███
███░████░███▄████████░███
▀██▄▀███░█████▄█████▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
FAZE CLAN
SSC NAPOLI
|
Mometaskers
Hero Member
*****
Offline Offline

Activity: 1764
Merit: 584



View Profile
October 28, 2017, 06:29:01 PM
 #3

It's good in a way, it shows they are being a bit proactive in protecting their website. However any hacker who could find exploits within coinbase could earn a heck of a lot more by draining all the bitcoin wallets stored there - depending on the severity of the hack found. It is more than a lot of exchanges out there are willing to do

I somewhat agree with this. If the vulnerability is severe enough that it would allow them to drain all the coins, then why bother with the 50k reward?

Still, this does allow them to find multiple minor bugs in one go so I think it's still worth it. Plus, it improves customer confidence.
BADecker (OP)
Legendary
*
Offline Offline

Activity: 3766
Merit: 1365


View Profile
October 28, 2017, 10:21:48 PM
 #4

It's good in a way, it shows they are being a bit proactive in protecting their website. However any hacker who could find exploits within coinbase could earn a heck of a lot more by draining all the bitcoin wallets stored there - depending on the severity of the hack found. It is more than a lot of exchanges out there are willing to do

I somewhat agree with this. If the vulnerability is severe enough that it would allow them to drain all the coins, then why bother with the 50k reward?

Still, this does allow them to find multiple minor bugs in one go so I think it's still worth it. Plus, it improves customer confidence.

They are watching for hackers. This exploits potential hackers because CB is tracking anyone who tries to hack to get the $50,000.

Cool

BUDESONIDE essentially cures Covid symptoms in one day to one week >>> https://budesonideworks.com/.
Hydroxychloroquine is being used against Covid with great success >>> https://altcensored.com/watch?v=otRN0X6F81c.
Masks are stupid. Watch the first 5 minutes >>> https://www.bitchute.com/video/rlWESmrijl8Q/.
Don't be afraid to donate Bitcoin. Thank you. >>> 1JDJotyxZLFF8akGCxHeqMkD4YrrTmEAwz
merchantofzeny
Sr. Member
****
Offline Offline

Activity: 1036
Merit: 279



View Profile
October 29, 2017, 02:27:53 PM
 #5

Well, this would expose the hackers who are in mostly for the money. I suppose white hat hackers might also try it out just for fun though. Since Coinbase get to choose which exploit to be rewarded, they'd get multiple exploits exposed at the same time (sorry for those hackers, no consolation prizes, LOL).

I just hope nothing severe is found. If I can find a way to take more than $50,000, then I will rather than bother with the smaller prize.
Mometaskers
Hero Member
*****
Offline Offline

Activity: 1764
Merit: 584



View Profile
October 30, 2017, 01:59:01 PM
 #6

It's good in a way, it shows they are being a bit proactive in protecting their website. However any hacker who could find exploits within coinbase could earn a heck of a lot more by draining all the bitcoin wallets stored there - depending on the severity of the hack found. It is more than a lot of exchanges out there are willing to do

I somewhat agree with this. If the vulnerability is severe enough that it would allow them to drain all the coins, then why bother with the 50k reward?

Still, this does allow them to find multiple minor bugs in one go so I think it's still worth it. Plus, it improves customer confidence.

They are watching for hackers. This exploits potential hackers because CB is tracking anyone who tries to hack to get the $50,000.

Cool

Well, let's just all hope that $50,000 is good enough for the hackers to share the vulnerabilities they found rather than exploit those for themselves.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!