ADVERTISEMENTREMOVE AD

Uber Offers Hackers ‘Treasure Map’ to Find Flaws in Its Software

The cab-aggregator technology company is looking to fine tune deficiencies in its software with this program.

Published
story-hero-img
i
Aa
Aa
Small
Aa
Medium
Aa
Large

Uber, the transportation firm, is releasing a technical map of its computer and communications systems and inviting hackers to find weaknesses in exchange for cash bounties.

While so-called “bug bounties” are not new, Uber’s move shows how mainstream companies are increasingly relying on independent computer researchers to help them bolster their systems.

Uber’s “Treasure Map” details the ride-hailing company’s software infrastructure, identifies what sorts of data might be exposed inadvertently and suggests what types of flaws are the most likely to be found.

“We’re wrapping up a lot of information and posting that to level the playing field so that it could be as easy for outside researchers to find flaws as us,” said Collin Greene, manager of security engineering at Uber.

ADVERTISEMENTREMOVE AD

Companies rarely say much about their proprietary programming, except to enable third parties to make compatible software.

“That’s a level of confidence that you have not seen too many closed-source software companies take in the past, and I’m really hopeful that others will follow suit,” said Alex Rice, chief technology officer at HackerOne, which is managing Uber’s bounty program.

HackerOne, a San Francisco rival called Bugcrowd and other startups have helped accelerate efforts to tap the independent security community to identify serious programming mistakes before criminals or spies do.

They can serve as intermediaries between researchers and companies, and sometimes vet their findings. A decade ago, hackers pointing out problems feared arrest but they can now earn modest sums from platforms like HackerOne.

Speaking truth to power requires allies like you.
Become a Member
Monthly
6-Monthly
Annual
Check Member Benefits
×
×