Facebook paid 330 security researchers $1.5M in 2013; adds Instagram, Parse, Atlas, Onavo to Bug Bounty program
Facebook today announced it paid out $1.5 million to 330 security researchers around the world in 2013 as part of its bug bounty program, which launched back in August 2011.
Context & Ripple Effects
When Facebook launched its bug bounty program in August 2011, it moved fast enough to pay out $40,000 to hackers within the first three weeks. Two and a half years on, the same program dispersed $1.5 million to 330 researchers across 2013 — a scale shift that turned an experiment into a line item, and the story was picked up widely enough that both Bloomberg and ZDNet ran it the same day.
The more strategically telling move is the scope expansion: by folding Instagram, Parse, Atlas and Onavo under the bounty umbrella, Facebook is extending its paid-disclosure perimeter across every property it operates, so a flaw found anywhere in the portfolio routes to Facebook's security team rather than to a black-market buyer.
First-order effects
- Instagram, Parse, Atlas and Onavo now carry the same cash rewards as facebook.com itself, immediately widening the attack surface independent researchers are financially incentivized to probe on Facebook's behalf.
- The 330 researchers who earned $1.5 million in 2013 now have a demonstrated, repeatable revenue channel from responsible disclosure, raising the opportunity cost of selling equivalent findings elsewhere.
Second-order effects
- Rival consumer web companies face pressure to stand up comparably funded bounty programs of their own, or cede first look at vulnerabilities in their own products to researchers whose best-paying customer is Facebook.
- Every acquisition widens the perimeter the program must cover — the Oculus VR purchase announced April 1, 2014 alone adds an entirely new hardware-and-software stack whose bugs will eventually need the same reward structure.
Third-order effects
- If annual payout disclosures become routine, they function as de facto industry benchmarks, normalizing crowdsourced vulnerability discovery as permanent security infrastructure rather than a goodwill gesture.
- A professional class of full-time bug hunters organized around platform payout programs takes shape, shifting vulnerability economics from exploit markets toward vendor-funded disclosure.
The trend: Bug bounty programs are hardening from PR-friendly experiments into standing security infrastructure that scales with each new product a platform company absorbs.