United Airlines offers hackers up to 1M mileage points to find vulnerabilities in its sites, apps, and online portals, but excludes testing of inflight systems
United Will Reward People Who Flag Security Flaws—Sort Of — United Airlines announced this week that it's launching …
Context & Ripple Effects
United's bounty lands weeks after a bruising episode: the FBI said researcher Chris Roberts claimed he could reach an in-flight entertainment system mid-flight, and United removed him from a flight. The new program is the airline converting that adversarial relationship into a managed channel — but only for its websites, apps, and online portals, with inflight systems explicitly off-limits.
The mileage-based reward is also a first among U.S. carriers, arriving just as intermediaries like HackerOne began taking a 20% commission to route white-hat reports to companies, making formal disclosure programs easier to stand up.
First-order effects
- Security researchers now have a sanctioned path to report United's web vulnerabilities in exchange for up to 1 million miles, instead of risking the treatment Roberts received.
- By carving out inflight systems, United draws a hard line between its customer-facing software and anything touching aircraft operations.
Second-order effects
- Two months later United had awarded millions of miles to hackers who surfaced real gaps, validating the model for other U.S. carriers.
- Uber followed within a year with a cash-based HackerOne program offering up to $10K per flaw, showing the format migrating from airlines' loyalty-currency payouts to standard bounties.
Third-order effects
- If the pattern holds, coordinated disclosure becomes table stakes across aviation — pressure underscored when researchers later found an e-ticketing flaw affecting eight-plus airlines including Southwest, the kind of cross-carrier exposure individual programs struggle with.
- Government adoption via DHS's Hack DHS bounty paying $500–$5,000 per flaw signals bug bounties hardening into standard security infrastructure beyond the private sector.
The trend: Bug bounties are spreading from tech firms into airlines and eventually government, with non-cash rewards like mileage points giving way to standardized paid programs run through intermediaries like HackerOne.