USENIX Security2023Top-tier venue
Bug Hunters' Perspectives on the Challenges and Benefits of the Bug Bounty Ecosystem
Omer Akgul, Taha Eghtesad, Amit Elazari, Omprakash Gnawali, Jens Grossklags, Michelle L. Mazurek, Daniel Votipka, Aron Laszka
Abstract
Although researchers have characterized the bug-bounty ecosystem from the point of view of platforms and programs, minimal effort has been made to understand the perspectives of the main workers: bug hunters. To improve bug bounties, it is important to understand hunters' motivating factors, challenges, and overall benefits. We address this research gap with three studies: identifying key factors through a free listing survey (n=56), rating each factor's importance with a larger-scale factor-rating survey (n=159), and conducting semi-structured interviews to uncover details (n=24). Of 54 factors that bug hunters listed, we find that rewards and learning opportunities are the most important benefits. Further, we find scope to be the top differentiator between programs. Surprisingly, we find earning reputation to be one of the least important motivators for hunters. Of the challenges we identify, communication problems, such as unresponsiveness and disputes, are the most substantial. We present recommendations to make the bug-bounty ecosystem accommodating to more bug hunters and ultimately increase participation in an underutilized market.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2cd5fcea-e522-4302-beee-b58cfe757740Cited by top-tier papers15
- The Benefits of Vulnerability Discovery and Bug Bounty Programs: Case Studies of Chromium and FirefoxSoodeh Atefi, Amutheezan Sivagnanam, Afiya Ayman, Jens Grossklags et al.WWW 2023 · 13 citations
- Unveiling the Hunter-Gatherers: Exploring Threat Hunting Practices and Challenges in Cyber DefensePriyanka Badva, Kopo M. Ramokapane, Eleonora Pantano, Awais RashidUSENIX Security 2024 · 13 citations
- ProphetFuzz: Fully Automated Prediction and Fuzzing of High-Risk Option Combinations with Only Documentation via Large Language ModelDawei Wang, Geng Zhou, Li Chen, Dan Li et al.CCS 2024 · 9 citations
- A Sea of Cyber Threats: Maritime Cybersecurity from the Perspective of MarinersAnna Raymaker, Akshaya Kumar, Miuyin Yong Wong, Ryan Pickren et al.CCS 2025 · 5 citations
- Credible Threat Detection? Measuring Contribution Dynamics and Quality Control in a Crowdsourced Threat Detection EcosystemApurva Virkud, Gang Wang, Adam BatesUSENIX Security 2026 · 1 citation
Builds on7
- Hackers vs. Testers: A Comparison of Software Vulnerability Discovery ProcessesDaniel Votipka, Rock Stevens, Elissa M. Redmiles, Jeremy Hu et al.S&P 2018 · 151 citations
- A Large-Scale Interview Study on Information Security in and Attacks against Small and Medium-sized EnterprisesNicolas Huaman, Bennet von Skarczinski, Christian Stransky, Dominik Wermke et al.USENIX Security 2021 · 30 citations
- A Large-Scale Measurement of Cybercrime Against IndividualsCasey F. Breen, Cormac Herley, Elissa M. RedmilesCHI 2022 · 26 citations
- HackEd: A Pedagogical Analysis of Online Vulnerability Discovery ExercisesDaniel Votipka, Eric Zhang, Michelle L. MazurekS&P 2021 · 22 citations
- The Benefits of Vulnerability Discovery and Bug Bounty Programs: Case Studies of Chromium and FirefoxSoodeh Atefi, Amutheezan Sivagnanam, Afiya Ayman, Jens Grossklags et al.WWW 2023 · 13 citations
Related papers
- A Deep Dive into How Open-Source Project Maintainers Review and Resolve Bug Bounty ReportsJessy Ayala, Steven Ngo, Joshua GarciaS&P 2025
- Study Club, Labor Union or Start-Up? Characterizing Teams and Collaboration in the Bug Bounty EcosystemYangheran Piao, Temima Hrle, Daniel W. Woods, Ross AndersonS&P 2025
- A Mixed-Methods Study of Open-Source Software Maintainers On Vulnerability Management and Platform Security FeaturesJessy Ayala, Yu-Jye Tung, Joshua GarciaUSENIX Security 2025
- IoT Bugs and Development ChallengesAmir Makhshari, Ali MesbahICSE 2021 · 76 citations
- The Shifting Sands of Motivation: Revisiting What Drives Contributors in Open SourceMarco Aurélio Gerosa, Igor Wiese, Bianca Trinkenreich, Georg Link et al.ICSE 2021 · 4 citations
