Making Markets for Information Security: The Role of Online Platforms in Bug Bounty Programs

04/14/2022
by   Johannes Wachs, et al.
0

Security is an essential cornerstone of functioning digital marketplaces and communities. If users doubt that data shared online will remain secure, they will withdraw from platforms. Even when firms take these risks seriously, security expertise is expensive and vulnerabilities are diverse in nature. Increasingly, firms and governments are turning to bug bounty programs (BBPs) to crowdsource their cybersecurity, in which they pay individuals for reporting vulnerabilities in their systems. And while the use of BBPs has grown significantly in recent years, research on the actors in this market and their incentives remains limited. Using the lens of transaction cost economics, this paper examines the incentives of firms and researchers (sometimes called hackers) participating in BBPs. We study the crucial role that centralized platforms that organize BBPs play in this emerging market. We carry out an analysis of the HackerOne BBP platform, using a novel dataset on over 14,000 researchers reporting over 125,000 public vulnerabilities to over 500 firms from 2014 to the end of 2021. We outline how platforms like HackerOne make a market for information security vulnerabilities by reducing information asymmetries and their associated transaction costs.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
05/24/2018

A Bug Bounty Perspective on the Disclosure of Web Vulnerabilities

Bug bounties have become increasingly popular in recent years. This pape...
research
01/28/2023

The Benefits of Vulnerability Discovery and Bug Bounty Programs: Case Studies of Chromium and Firefox

Recently, bug-bounty programs have gained popularity and become a signif...
research
03/31/2023

Decentralized Attack Search and the Design of Bug Bounty Schemes

Systems and blockchains often have security vulnerabilities and can be a...
research
12/22/2021

Security Risks of Porting C Programs to WebAssembly

WebAssembly is a compilation target for cross-platform applications that...
research
06/01/2020

Security Smells in Android

The ubiquity of smartphones, and their very broad capabilities and usage...
research
05/09/2018

Loyalty Programs in the Sharing Economy: Optimality and Competition

Loyalty programs are important tools for sharing platforms seeking to gr...
research
08/05/2023

A Study of China's Censorship and Its Evasion Through the Lens of Online Gaming

For the past 20 years, China has increasingly restricted the access of m...

Please sign up or login with your details

Forgot password? Click here to reset