gratipay / inside.gratipay.com

Here lieth a pioneer in open source sustainability. RIP
https://gratipay.news/the-end-cbfba8f50981
57 stars 38 forks source link

publish something about our security program #560

Closed chadwhitacre closed 8 years ago

chadwhitacre commented 8 years ago

Reticketed from https://github.com/gratipay/inside.gratipay.com/issues/558#issuecomment-206426101.

We've put a lot of effort over the past few months into setting up our HackerOne program. Let's blog about it!

Draft 1: "An Open Vulnerability Program: Announcing Gratipay on HackerOne"

chadwhitacre commented 8 years ago

Draft 1: "An Open Vulnerability Program: Announcing Gratipay on HackerOne"

TheHmadQureshi commented 8 years ago

Awesome! 👍

chadwhitacre commented 8 years ago

I've been tinkering with Draft 1 rather than making a new draft.

chadwhitacre commented 8 years ago

Is it too bold to title this, "A New Standard in Transparent Security"?

chadwhitacre commented 8 years ago

Maybe just "Transparent Security"

chadwhitacre commented 8 years ago

Any objections to publishing?

"Transparent Security: Introducing Gratipay's Program on HackerOne"

chadwhitacre commented 8 years ago

Alright, here we go ...

chadwhitacre commented 8 years ago

I added some stats. A quarter of our reports are duplicates, and half our reports are low-quality.

chadwhitacre commented 8 years ago
chadwhitacre commented 8 years ago

screen shot 2016-04-08 at 11 09 43 am

chadwhitacre commented 8 years ago

screen shot 2016-04-08 at 11 28 28 am

chadwhitacre commented 8 years ago

Two points make a line? :-)


logo-049c93004a425a8472da247aa44c4edd

https://hackerone.com/blog/uber-launches-first-of-its-kind-hacker-loyalty-program-with-hackerone-bonuses


hackerone-logo-300x206

https://blog.newrelic.com/2016/03/14/responsible-disclosure-security/

chadwhitacre commented 8 years ago

screen shot 2016-04-08 at 12 34 44 pm

chadwhitacre commented 8 years ago

Ready? I think we're ready ...

chadwhitacre commented 8 years ago

Published! :flushed:

https://twitter.com/Gratipay/status/718480331666550784

chadwhitacre commented 8 years ago

I've received a kind note in private email from HackerOne's CEO. I've asked him if I can share it here.

chadwhitacre commented 8 years ago

Kudos to the Gratipay team for the Transparent Security blog posting. It should be essential reading for anyone doing bug bounty programs or vulnerability coordination. You don't know how proud we are to have you on the H1 platform!

chadwhitacre commented 8 years ago

Also some encouraging feedback on Twitter:

@whit537 Nice article about the @Gratipay bounty program!

https://twitter.com/mrusschen/status/718485981075283971

Holy cow @Gratipay, this is a goldmine of feedback. Great writeup!

https://twitter.com/Magoo/status/718487174350409728