Skip to main content

Yelp is offering ‘nice’ hackers up to $15,000 to squash its bugs

yelp bug bounty program
Image used with permission by copyright holder
White-hat hackers take note – another money-making opportunity has just landed.

Review site Yelp has, perhaps not before time, announced a public bug bounty program with a top payout of $15,000.

Recommended Videos

Security experts have been invited by Yelp to dig into its range of desktop and mobile sites to uncover weaknesses and flaws that could allow nefarious types to wreak havoc on its vast online business.

Yelp guarantees a minimum payout of $100 for every accepted report, though should you uncover the kind of critical flaw that would ordinarily cause a serious-minded developer to break into a cold sweat at the mere thought of its existence, you could be in line for the top cash award of $15,000. Or something close to it.

The online review giant is running its bug bounty program with HackerOne, a Silicon Valley firm that offers such services. A webpage dedicated to the Yelp program offers updates on payouts, and a quick look shows that in less than 24 hours two hackers have already picked up $100 each for their efforts.

This latest bug-squashing venture is actually an expansion of a private bug bounty program that Yelp launched two years ago. That one helped the company identify and fix more than 100 potential vulnerabilities, but it hopes that taking the program public will help it quickly close down any remaining weaknesses lurking in the depths of its online services.

Aware of the mind-blowing talent of some researchers, Yelp is asking bug hunters to “please be nice to us.” On its HackerOne page, the San Francisco-based company says, “We want you to bring out your big guns, but hold off on actually breaking anything. Please avoid DDoS’ing us or breaking our systems and services while you are testing.”

Yelp has posted an additional article laying out exactly what it wants security researchers to look for, so if you enjoy tinkering under the hood and are up for a challenge, go check it out.

Trevor Mogg
Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
Google’s Android bug bounty program announces a $1 million prize
pixel 4 xl screen vs pixel 3 xl screen

Google has been handing out cash rewards to Android bug hunters since 2015 in an effort to keep the mobile operating system safe and secure and running smoothly.

This week the Mountain View, California-based company announced it is increasing its top payout to a whopping $1 million, with a potential for a 50% bonus that pushes it to $1.5 million.

Read more
NASA tests new AI chatbot to make sense of complex data
An Earth image captured by NASA.

Using its Earth-observing satellites, NASA has collected huge amounts of highly complex data about our planet over the years to track climate change, monitor wildfires, and plenty more besides.

But making sense of it all, and bringing it to the masses, is a challenging endeavor. Until now, that is.

Read more
Corsair just spilled the beans on next-gen GPU requirements
Nvidia GeForce RTX 4090 is shown along with a hand holding the power cable adapter.

Sometimes, news about next-gen GPUs comes from unlikely sources -- today is one of those days. Corsair just spoke about its power supply units (PSUs) and cooling solutions in relation to the future of some of the upcoming best graphics cards. It turns out that Nvidia's RTX 50-series may not be that much more power-hungry than the current-gen cards, but there's more than just Nvidia to consider here.

Although unexpected, Corsair's statement sounds like good news. The company doesn't talk about any new solutions. In fact, Corsair seems to confirm that the power supply units (PSUs) we use today will still work fine for next-gen cards -- provided the wattage is sufficient.

Read more