/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

United Airlines offers hackers up to 1M mileage points to find vulnerabilities in its sites, apps, and online portals, but excludes testing of inflight systems

United Will Reward People Who Flag Security Flaws—Sort Of  —  United Airlines announced this week that it's launching …

Wired Kim Zetter

Context & Ripple Effects

United's bounty lands weeks after a bruising episode: the FBI said researcher Chris Roberts claimed he could reach an in-flight entertainment system mid-flight, and United removed him from a flight. The new program is the airline converting that adversarial relationship into a managed channel — but only for its websites, apps, and online portals, with inflight systems explicitly off-limits.

The mileage-based reward is also a first among U.S. carriers, arriving just as intermediaries like HackerOne began taking a 20% commission to route white-hat reports to companies, making formal disclosure programs easier to stand up.

First-order effects

  • Security researchers now have a sanctioned path to report United's web vulnerabilities in exchange for up to 1 million miles, instead of risking the treatment Roberts received.
  • By carving out inflight systems, United draws a hard line between its customer-facing software and anything touching aircraft operations.

Second-order effects

Third-order effects

The trend: Bug bounties are spreading from tech firms into airlines and eventually government, with non-cash rewards like mileage points giving way to standardized paid programs run through intermediaries like HackerOne.