• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Pentagon accuses Alibaba, Baidu and BYD, three of China's biggest companies, of supporting the Chinese military

2

Analysts expected oil to surge above $200 but China has quietly kept prices half of that—and can’t for much longer

3

Costco CEO Ron Vachris rose from forklift driver to the C-suite without a college degree: ‘Don’t chase a title’ is the career advice that got him there

1

Pentagon accuses Alibaba, Baidu and BYD, three of China's biggest companies, of supporting the Chinese military

2

Analysts expected oil to surge above $200 but China has quietly kept prices half of that—and can’t for much longer

3

Costco CEO Ron Vachris rose from forklift driver to the C-suite without a college degree: ‘Don’t chase a title’ is the career advice that got him there
TechPointCloud

Startup Offers Free ‘Bug Bounty’ Help to Open Source Projects

Jeff John Roberts
By
Jeff John Roberts
Jeff John Roberts
Editor, Finance and Crypto
Down Arrow Button Icon
Jeff John Roberts
By
Jeff John Roberts
Jeff John Roberts
Editor, Finance and Crypto
Down Arrow Button Icon
March 2, 2017, 9:50 AM ET
photography by Albert Law : www.porkbellystudio.com
photography by Albert Law : www.porkbellystudio.comPhotograph by Albert Law

Many people don’t realize much of the Internet is built on free software. Even giant companies like Facebook, Google, and Amazon rely extensively on big libraries of code—known as “open source” software”—written by thousands of programmers, who share their work with everyone.

But no software is perfect. Like the proprietary code developed by many companies, open source software contains flaws that hackers can exploit to steal information or spread viruses. That’s why a new initiative to patch those holes is important.

On Thursday, a startup called HackerOne announced it will offer its bug bounty management services, which helps discover flaws in software, to open source projects free of charge.

If you’re unfamiliar, bug bounties work by offering altruistic hackers a reward (typically cash) to disclose software vulnerabilities they discover. The bounties are offered by a growing number of companies, from Apple to General Motors, and are effective because they let companies patch software problems before a malicious hacker can find and exploit them first.

While there is already such a program for open source projects, called The Internet Bug Bounty, the new HackerOne initiative is likely to direct more attention to these projects.

The reason is because HackerOne, which just raised a $40 million investment round in February, acts as a hub for a huge community of hackers, who use the company as a conduit to report their discoveries. Acting as an intermediary, HackerOne takes the information it gets from the hackers and presents it to those responsible for software—who in turn use HackerOne to distribute the rewards.

Get Data Sheet, Fortune’s technology newsletter.

In a blog post announcing the new initiative, HackerOne noted that many open source projects—such as Ruby, Rails, Discourse, Django, GitLab, Brave, and Sentry—are already using the company’s services. HackerOne also encouraged other open source projects, including lesser known ones, to apply to be included as well.

“Put simply, eligible open source projects will receive the powerful HackerOne Professional service for free. This will provide vulnerability submission, coordination, dupe detection, analytics, and bounty programs for your projects. It greatly simplifies how you define scope, receive vulnerability reports, manage those reports, and incentivize security researchers to help harden your project,” said the company.

Here is a screenshot that shows a sample of the dashboard HackerOne provides to its users to discuss vulnerabilities:

HackerOne screenshot

In an interview with Fortune, HackerOne CEO Marten Mickos says the company regards its new initiative, called Community Edition, as a way of giving back. Just as other companies such as Amazon Web Services (AMZN) and GitHub provide open source projects with services free of charge, Mickos says HackerOne wants to do the same on the bug bounty front.

As for rewards, Mickos says cash bounties will come from the Internet Bug Bounty but that, in his experience, that will often be unnecessary.

“Many hackers say, ‘If it’s an open source project, I’ll hack for free. A lot of that goes on. There’s so many good people out there,” he says.

Mickos also notes open source projects typically result in stronger software because they are built with more collaboration. But he hopes the new HackerOne initiative will provide a way for the projects to ask hackers for extra help in boosting their security.

“Coming from the open source world myself, I know you don’t push your solution,” Mickos says. “You show your value, and they will come to you.”

About the Author
Jeff John Roberts
By Jeff John RobertsEditor, Finance and Crypto
LinkedIn iconTwitter icon

Jeff John Roberts is the Finance and Crypto editor at Fortune, overseeing coverage of the blockchain and how technology is changing finance.

See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

SpaceX’s record IPO has Wall Street torn between a Musk ‘holy grail’ and a $72-per-share leap of faith
Startups & VentureSpaceX
SpaceX’s record IPO has Wall Street torn between a Musk ‘holy grail’ and a $72-per-share leap of faith
By Marco Quiroz-GutierrezJune 11, 2026
59 minutes ago
Bridgit Mendler speaks on stage at Fortune Brainstorm Tech 2026 in Aspen, Colorado.
Startups & VentureBrainstorm Tech
The space economy’s next frontier is in ground infrastructure, Northwood Space CEO says
By Sebastian HerreraJune 10, 2026
6 hours ago
Digital sovereignty isn’t the same thing as digital isolation. Asia’s governments should be careful
Commentarydata sovereignty
Digital sovereignty isn’t the same thing as digital isolation. Asia’s governments should be careful
By Leonard LimJune 10, 2026
11 hours ago
Microsoft co-founder Bill Gates (C) arrives for a closed-door interview with the House Oversight Committee on Capitol Hill in Washington, DC, on June 10, 2026.
LawBill Gates
Gates testifies on Epstein: previous Fortune investigation reveals payments to his ex-girlfriend, $1M Microsoft deal
By Eva Roytburg, Joey Cappelletti, Hannah Schoenbaum and The Associated PressJune 10, 2026
12 hours ago
How the World Cup is a high-stakes stage for Big Tech’s AI push
NewslettersCIO Intelligence
How the World Cup is a high-stakes stage for Big Tech’s AI push
By John KellJune 10, 2026
13 hours ago
Anthropic accused of ‘secret sabotage’ as Claude Fable 5 silently limits capabilities for AI researchers and developers
AIAnthropic
Anthropic accused of ‘secret sabotage’ as Claude Fable 5 silently limits capabilities for AI researchers and developers
By Sharon GoldmanJune 10, 2026
14 hours ago

Most Popular

Pentagon accuses Alibaba, Baidu and BYD, three of China's biggest companies, of supporting the Chinese military
Asia
Pentagon accuses Alibaba, Baidu and BYD, three of China's biggest companies, of supporting the Chinese military
By Kate O'Keeffe and BloombergJune 8, 2026
2 days ago
Analysts expected oil to surge above $200 but China has quietly kept prices half of that—and can’t for much longer
Energy
Analysts expected oil to surge above $200 but China has quietly kept prices half of that—and can’t for much longer
By Sasha RogelbergJune 10, 2026
14 hours ago
Costco CEO Ron Vachris rose from forklift driver to the C-suite without a college degree: ‘Don’t chase a title’ is the career advice that got him there
Success
Costco CEO Ron Vachris rose from forklift driver to the C-suite without a college degree: ‘Don’t chase a title’ is the career advice that got him there
By Preston ForeJune 8, 2026
3 days ago
Marc Lore’s robots make 500 burrito bowls an hour. A human can make 45
Innovation
Marc Lore’s robots make 500 burrito bowls an hour. A human can make 45
By Amanda GerutJune 9, 2026
1 day ago
Current price of oil as of June 10, 2026
Personal Finance
Current price of oil as of June 10, 2026
By Joseph HostetlerJune 10, 2026
19 hours ago
A ‘MAGA Warrior’ Texas ag chief is publicly blasting the USDA over a flesh-eating pest threatening America's beef supply
North America
A ‘MAGA Warrior’ Texas ag chief is publicly blasting the USDA over a flesh-eating pest threatening America's beef supply
By Marco Quiroz-GutierrezJune 10, 2026
22 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.