Dropbox opens a paid bug bounty program
Dropbox is now running a public bug bounty program through HackerOne, offering monetary rewards to security researchers who responsibly disclose vulnerabilities in its products. The move formalizes and expands on work the company has already been doing with external researchers, whose contributions it previously acknowledged only through a public hall of fame.
The company has long used professional penetration-testing firms and in-house testing, but says independent scrutiny from the wider security community has been valuable enough to justify direct payouts. The initial retroactive payments made through the existing reporting process totaled $10,475. Individual payments so far range from a $216 minimum for qualifying bugs to a maximum of $4,913, with no official cap on the bounty amount.
For now, the program covers the Dropbox, Carousel, and Mailbox iOS and Android apps; the Dropbox and Carousel web apps; the Dropbox desktop client; and the Dropbox Core SDK. Dropbox may also reward researchers who find novel or particularly interesting bugs in other applications it operates. As with most programs, only the first report of a duplicate vulnerability earns a reward.
The program is the latest step in Dropbox's broader security efforts, which have included recognition from the EFF and SSL Labs and support for the SimplySecure initiative. Full rules and submission guidelines are available on the HackerOne page.



