Dropbox Takes Live Bug Hunting to Amsterdam
Dropbox has spent 2018 refining its bug bounty program, and one of the more ambitious experiments came in the form of a live-hacking event hosted with HackerOne in Amsterdam. The H1-3120 gathering brought researchers together in person to probe Dropbox's systems, with bounties paid out on the spot. The format paid off: the company doubled its previous single-day record for bounty payouts and walked away with a pile of high-quality vulnerability reports.
Planning for the event centered on three goals: expanding the attack surface available to researchers, keeping communication fast and frictionless, and giving hackers enough context to hunt effectively in a compressed timeframe.
Expanding the Scope
Dropbox's bug bounty program already aims to be among the most permissive in the industry, but for H1-3120 the company went further. Five SaaS vendors that Dropbox works with were placed in scope for the event, with Dropbox handling triage and paying out bounties for any valid findings. This marked the first time a HackerOne live-hacking event had included third-party vendors in its scope.
The rationale was straightforward: Dropbox holds vendors with access to sensitive data to high security standards, and that includes a willingness to be scrutinized by outside researchers. Opening up those vendors to the event's hackers was a natural extension of that policy.
Communication and Guidance
Rather than letting researchers work in a vacuum, Dropbox set up a Slack channel staffed in the week before the event so participants could ask questions during their reconnaissance phase. A conference call with the hackers provided another opportunity for Q&A and advice ahead of the main event.
To give researchers a running start, Dropbox also shared examples of past vulnerabilities and pointed to areas of the product that the security team considered highest-risk. The idea was to direct attention toward parts of Dropbox that see less frequent testing, which benefits both the researchers looking for bugs and Dropbox itself.
The Event Itself
Submissions started flooding in as soon as H1-3120 opened. In the first 30 minutes alone, more than 50 reports were filed, ranging from straightforward information disclosure to cross-site scripting. The most severe finding was a remote code execution vulnerability discovered in the perimeter of one of the vendors in scope.
By the time the event wrapped up, Dropbox had paid out over $80,000 in bounties, with more than $5,000 of that going to charity. The total represented a new single-day record for the program.
Post-Event Momentum
The effects of H1-3120 didn't end when the payouts were made. Since the event, Dropbox has seen a 23% uptick in daily bug bounty submissions. One report from researcher detroitsmash earned a $9,000 bounty.
The relationships formed during the event have also proven valuable. Conversations with frequent bug bounty participants have led to additional HackerOne reports that Dropbox subsequently awarded on, and the company plans to keep building on those connections with recurring researchers.
For Dropbox, the takeaway is that live-hacking events are more than just a concentrated burst of vulnerability hunting. They're also a way to strengthen the broader security community and keep the bug bounty pipeline healthy long after the event ends.



