Skip to main content

Uber launches bug bounty program with top prize of $10,000

uber bug bounty program
Image used with permission by copyright holder
Uber is the latest company to launch its own bug bounty program for white hat hackers with rewards of up to $10,000 for discovering serious flaws.

From May 1, security researchers will have three months to research and disclose any vulnerabilities they can find in Uber’s websites and apps. Uber is making public what it calls a “treasure map” of its code to help security researchers examine the code for any issues. The bug bounty program was previously in beta but will now be open to anyone to try.

Recommended Videos

Multiple bugs found will result in bonus rewards to encourage hackers to stay loyal to Uber and continue scrutinizing its security for the better. Some of the vulnerabilities it is looking for include cross-site scripting and SQL injection.

Hackers will have to privately disclose their findings to Uber and only after the bug has been patched will the details be made public.

Critical vulnerabilities will pay $10,000, and include things like remote code execution or exposing user data. “Significant issues” such as cross-site scripting and failed authentication features will pay $5,000, while “medium issues” will pay $3,000 for less serious bugs that don’t expose any personal identifiable information (PII) on users.

The bug bounty program comes after Uber experienced its fair share of security problems. A 2014 data breach exposed 50,000 Uber drivers’ personal details. The company failed to act on it for months and ultimately paid a $20,000 fine in the state of New York. The source of the breach even led to accusations involving Uber’s competitors.

Meanwhile compromised user accounts have been spotted on the dark Web selling for as little as a $1 apiece with few details on how exactly they were breached. Finally, in an embarrassing episode in January the personal information, including a social security number, of one Uber driver in Florida was accidentally sent out to thousands of other drivers.

Jonathan Keane
Former Digital Trends Contributor
Jonathan is a freelance technology journalist living in Dublin, Ireland. He's previously written for publications and sites…
I have a theory on how the PS5 Pro could actually outclass PCs
The PS5 Pro suspended in air.

Without a doubt, the PlayStation 5 Pro is the most powerful game console we've ever seen. It's set to launch next week, promising "45% faster rendering" on the back of a beefier graphics card and faster memory. It won't be enough to outclass a proper gaming desktop packing one of the best graphics cards -- not even close. But the PS5 Pro could have an edge over PCs in one area.

I say "could" because we really don't know. AMD pointed me to Sony, and Sony hasn't returned my request for comment about the specifics under the hood of the PS5 Pro. I have some hints, however, and if you'll indulge a little speculation, I have some interesting theories about how the PS5 Pro might have an edge over even powerful gaming PCs.
The PS5 Pro's secret weapon

Read more
Intel Battlemage GPU: everything we know so far
Intel Arc A770 GPU installed in a test bench.

Despite a rocky start, Intel's Arc GPUs are now among the best graphics cards you can buy. Targeting budget PC gamers, Intel has established itself as a major player in gaming graphics cards, and all eyes are on Team Blue with its next generation of GPUs, codenamed Battlemage.

We know Battlemage GPUs are coming, and Intel has slowly been dropping hints about the graphics cards over the past year. Although we're still waiting on an official release date, specs, and pricing details for Battlemage GPUs, there's a lot we can piece together already.
Intel Battlemage: specs

Read more
Spotify vs. Pandora: which streaming service should you choose?
spotify vs pandora on iphone

Let's settle a musical debate: which music streaming platform should you use: Spotify or Pandora?

Both services have their unique strengths and weaknesses. Spotify boasts a more extensive music catalog, robust social features for sharing and discovering music with friends, and a more polished user experience across devices.

Read more