• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechCyber Saturday

Cyber Saturday—Coinbase Loves Hackers, Facebook Election Win, White House Video Fake Out

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
November 10, 2018, 11:56 PM ET

Bug bounty programs were a major topic of discussion during a panel I moderated on risk management at the Money20/20 finance and tech conference in Las Vegas a couple weeks ago. These programs compensate hackers for poking holes in a company’s products and finding and reporting any vulnerabilities to the people who can fix them. Ideally, they help companies root out flaws in their code and hardware, making the world safer for businesses and consumers.

My panelists were Philip Martin, head of security at Coinbase, the cryptocurrency exchange privately valued at $8 billion, and Mårten Mickos, CEO of HackerOne, a startup that helps companies set up and manage bug bounty programs. (Coinbase has had a bug bounty program in place since its founding in 2012; it’s a customer of HackerOne.)

Here are some of the session’s highlights.

  • Citing research by Katie Moussouris, former chief policy officer of HackerOne, I noted that the rewards offered by the “good guys” can never compete with those offered by black market brokers, who will pay a premium for severe vulnerabilities. Mickos pushed back against this assertion, arguing that while some ultra-bad bugs can reap up to a million dollars or more, the vast majority of bugs are more trivial and fetch far less.
  • Martin poopooed artificial intelligence as a cure-all for the world’s cybersecurity ills. There are certain things that computers are good at and certain things that humans are good at; the worst bugs demand human ingenuity to uncover and, he said, security professionals should teach these skills through apprenticeship.
  • One reason why Coinbase chooses to release the majority of its bug reports to the public is to provide other researchers an invaluable resource for learning. Transparency becomes a way to give back to the community and foster talent.
  • The credit and recognition afforded by public reports also helps incentivize hackers to report vulnerabilities to companies, rather than sell their findings to shadier brokers. Bug hunters can use the reputations they build on platforms like HackerOne to land jobs, Mickos said.
  • Companies should only put bug bounty programs in place once they have the basics down—meaning after they’ve attained maturity in their vulnerability management process, Martin said. How does one know when one has reached that point? His answer: When there are no longer emergencies.

By the way, Martin helps run the custodial program that Coinbase uses to secure its customers’ crypto wealth. It involves using a pop-up, metal-lined tent as a Faraday cage within which to perform secret cryptographic operations. I recommend reading Wired’s detailed write-up of the ceremony. The procedure is wacky and delightful—and Martin told me it’s one of his favorite parts of his job.

Have a great weekend.

Robert Hackett

@rhhackett

robert.hackett@fortune.com

Welcome to the Cyber Saturday edition of Data Sheet, Fortune’s daily tech newsletter. Fortune reporter Robert Hackett here. You may reach Robert Hackett via Twitter, Cryptocat, Jabber (see OTR fingerprint on my about.me), PGP encrypted email (see public key on my Keybase.io), Wickr, Signal, or however you (securely) prefer. Feedback welcome.

THREATS

You're outta here! Facebook said it removed 115 accounts suspected of engaging in "coordinated inauthentic behavior" from its flagship site as well as Instagram in the lead-up to the midterm elections in the U.S. Nathaniel Gleicher, Facebook's cybersecurity policy leader, said the company had been tipped off about the allegedly bogus accounts by law enforcement last weekend. Meanwhile, trolls have been struggling to spread their misinformation on Twitter, NBC News reports.

Doctor, doctor, give me the news. The White House appeared to share a doctored video as justification for its ban of CNN reporter Jim Acosta. The video in question, which sped up Acosta's arm movement to make it appear as though he were karate chopping a White House intern, was first shared online by a known conspiracy theorist.

Iran so far away. Banks are on high alert for attacks by Iranian hackers in the wake of the U.S.'s reinstatement of economic sanctions on Iran. The middle eastern nation "might lash out," as one top cybersecurity executive put it to CNN, which got a glimpse of a major bank's cybersecurity defense center.

Cylance of the lambs. BlackBerry is reportedly in talks to gobble up cybersecurity firm Cylance for as much as $1.5 billion, Business Insider reported. The business news site's sources said the deal could happen as soon as next week—although it could just as easily fall apart.

Fun in the sun. U.S. Cyber Command, a hacking-focused division of the military, began releasing unclassified malware samples to the public as part of a cybersecurity information sharing initiative on Friday. The command posted two code samples to the Google-owned malware research repository VirusTotal, including one sample that it said originated from the suspected Russian espionage group nicknamed "fancy bear," which was best known for digitally infiltrating the Democratic National Committee in 2016.

"Naynay on those n00bes."

Share today's Cyber Saturday with a friend:

http://fortune.com/newsletter/cybersaturday/

Looking for previous Data Sheets? Click here

ACCESS GRANTED

All quiet on the western front? Facebook HQ was relatively calm on the day of the U.S. midterm elections, despite fears that trolls would promote viral misinformation to influence voters. A lot of work went into making this so: a constantly staffed "war room," investigative journalists and other good samaritans regularly reporting fake news to the company, regulator scrutiny, and more. Kevin Roose at the New York Times took the opportunity to urge people to continue to hold the company accountable, or else the media giant may lapse into its old bad habits.

After an Election Day largely free of viral social media misinformation, and with little trace of the kind of Russian troll stampede that hit its platform in 2016, executives at Facebook may be tempted to take a victory lap. That would be a mistake.

It’s true that Facebook and other social media companies have made strides toward cleaning up their services in the last two years. The relative calm we saw on social media on Tuesday is evidence that, at least for one day, in one country, the forces of chaos on these platforms can be contained. But more than anything, this year’s midterm election cycle has exposed just how fragile Facebook remains.

FORTUNE RECON

Austrian Government Says Colonel May Have Been Russian Spy For Decades by David Meyer

White House Press Secretary Shares Fake Infowars Video to Justify Banning CNN Reporter by Erin Corbett

Facebook Is the Least Trusted Major Tech Company When it Comes to Safeguarding Personal Data, Poll Finds by Jonathan Vanian

Privacy Activists Take On Oracle and Equifax Over Shadowy Profiling by David Meyer

Legal Sports Gambling Could Attract Criminals. Here’s How to Stop Them by Rick McDonell

Here's What Mastercard's Chief Privacy Officer Thinks About GDPR by Erika Fry

Credit Card Chips Fail to Halt Fraud, Survey Says by Jeff John Roberts

Microsoft Will Not Use Personal Data For Profit, Says Satya Nadella by Grace Dobush

ONE MORE THING

Tear here. A Swedish national named Jermu Michael Salonen, 43, is reported to have sent a homemade bomb to employees of a Bitcoin company in London. Last year Salonen had demanded that the company, Cryptopay, send him a new password—a demand the company refused, saying this action would breach its privacy policy. One law enforcement officer quoted by the BBC said the only reason no one was harmed was because of how the package was opened: "It was due to sheer luck that the recipient ripped opened the package in the middle rather than using the envelope flap which would have activated the device."

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
Fortune Secondary Logo
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

AIbehavioral economics
Nobel laureate Joseph Stiglitz warns AI’s hunger for internet comments could degrade the world’s ‘information ecosystem’
By Catherina GioinoMarch 9, 2026
3 hours ago
People wait outside a building
AIJobs
AI layoffs are coming. The problem may be compounded because nearly 75% of people don’t apply for unemployment benefits
By Jacqueline MunisMarch 9, 2026
4 hours ago
A plume of smoke rises from the port of Jebel Ali following a reported Iranian strike in Dubai on March 1, 2026.
Middle EastData centers
Iran’s attacks on Amazon data centers in UAE, Bahrain signal a new kind of war as AI plays an increasingly strategic role, analysts say
By Jeremy KahnMarch 9, 2026
6 hours ago
Anthropic CEO Dario Amodei speaking into a microphone.
LawAnthropic
Anthropic sues the Pentagon after being labeled a threat to national security
By Beatrice NolanMarch 9, 2026
6 hours ago
Photo of Peter Diamandis
InnovationEntrepreneurship
Billionaire Peter Diamandis offers $3.5 million to filmmakers who portray AI as the hero—not the villain
By Marco Quiroz-GutierrezMarch 9, 2026
6 hours ago
Business man on the phone with luggage
SuccessCareers
European companies using AI are hiring more workers, not cutting them—and Americans are already relocating there to escape uncertainty
By Preston ForeMarch 9, 2026
7 hours ago

Most Popular

placeholder alt text
Success
Gen Z graduates who majored in ‘AI-proof’ careers like pharmacy, biology, and education are making less than $50,000 after graduation
By Emma BurleighMarch 6, 2026
3 days ago
placeholder alt text
Success
This AI founder who quit her 9-to-5 law job has a warning for anyone dreaming of doing the same: 'I'm working harder now than I ever did'
By Emma BurleighMarch 8, 2026
2 days ago
placeholder alt text
AI
Anthropic just mapped out which jobs AI could potentially replace. A 'Great Recession for white-collar workers' is absolutely possible
By Jake AngeloMarch 6, 2026
3 days ago
placeholder alt text
Real Estate
Billionaires Elon Musk and Mark Zuckerberg used mortgages to buy multimillion-dollar mansions. Here’s why that’s a savvy financial decision
By Sydney LakeMarch 9, 2026
8 hours ago
placeholder alt text
Energy
'Nightmare scenario' looms as global markets head for the biggest oil output disruption in history, top energy guru warns
By Jason MaMarch 8, 2026
1 day ago
placeholder alt text
Energy
Trump promised to fill America’s oil reserves ‘right to the top.’ A year later, oil has exceeded $100 and they’re still less than 60% full
By Tristan BoveMarch 9, 2026
6 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.