Slashdot Mirror


Yelp Launches Public Bug Bounty Program (techcrunch.com)

Yet another company has launched a public bug bounty program to lure in hackers in an effort to find and eradicate vulnerabilities. Yelp is the latest company to do such a thing. Specifically, they are inviting hackers to dissect its websites and mobile application and look for vulnerabilities that could affect reviewers and businesses. In return, they will pay "researchers" who find vulnerabilities, starting at $100 and maxing out at $15,000 "for more complex and critical exploits." TechCrunch reports: "The program, which Yelp is coordinating through the bug bounty platform HackerOne, is a public extension of a bug bounty system that Yelp has privately run for two years. The private version was open to dozens of researchers, who uncovered more than 100 vulnerabilities for Yelp and earned $65,160 in total, and focused primarily on Yelp's main website. Now, Yelp is inviting everyone to test Yelp sites and products. Yelp, which averages 73 million unique visitors to its desktop site and 63 million unique visitors on mobile each month, is asking hackers to cover broad ground -- the bug bounty program includes the company's main website, yelp.com, as well as its business-owners website, apps, reservation platform, corporate blogs, support center, and API."

14 comments

  1. Here's a solution instead by xushi · · Score: 1

    Have your website done entirely in JPEG.

    1. Re:Here's a solution instead by Anonymous Coward · · Score: 0

      the whole fucking site is a bug. delete yelp.com from the internet root dns. done. i found the biggest problem, i delivered the best possible fix for said problem, now pay up. instead of sending me a bounty, run around the outside of your soon-to-be vacated office, nekkid, with a sign that reads 'yelp is a scam' and never touch the internet or a computing 'device' ever again.

    2. Re:Here's a solution instead by JamesKeane7745 · · Score: 1

      Nice try at looking clever, but .com is in the root zone file, not yelp.com. Please, please, please never do any DNS work on any issues I haNXDOMAIN.

  2. I report www.yelp.com by Anonymous Coward · · Score: 0

    Do I win?

    1. Re:I report www.yelp.com by justthinkit · · Score: 2

      I came here to say the same thing.

      Was there ever a more extortionistic web site?

      Just for starters, there is no down mod on user comments. And by the way, Amazon removed the down mod on user comments just a few months back. Think about the effect that has...it isn't good.

      Also, if you say something highly praiseworthy, Yelp is likely to move your comment to the bottom so no one ever sees it. Of course, you can no doubt BUY a better positioning on Yelp...

      --
      I come here for the love
  3. Bug #0 by Anonymous Coward · · Score: 0

    Bug #0 is Yelp's business model: suppress positive reviews (and rank negative reviews higher) for businesses that don't pay the protection fee; hide negative reviews (and rank positive reviews higher) for businesses who do pay the protection fee. Yelp is a fucking scam.

  4. waste of time by Anonymous Coward · · Score: 0

    Biased paid-for reviews with narrow geographic coverage. Yelp on my phone stopped working unless on wifi, and I even reinstall wont' fix that. Searching for security vulnerabilities for an app like that is a waste of time even if they pony up cash for that.

  5. Fail. by Anonymous Coward · · Score: 0

    Less and less reasons to come to this site.

  6. Bug Bounties by fustakrakich · · Score: 1

    All they do is raise the price on the black market.

    --
    “He’s not deformed, he’s just drunk!”
    1. Re:Bug Bounties by ShanghaiBill · · Score: 1

      All they do is raise the price on the black market.

      Isn't that a good thing?

    2. Re:Bug Bounties by fustakrakich · · Score: 1

      Well yeah, for some people it definitely is. Problem is, what I forgot to mention before, if you try to go the "legitimate" route as the good samaritan, you risk getting arrested if you don't report the bugs anonymously and you try to collect the bounty. Why take that kind of chance?

      --
      “He’s not deformed, he’s just drunk!”
  7. Too cheap by Anonymous Coward · · Score: 0

    Mutiply by those bounties times 10-100.

  8. I already report bugs to Yelp. by mr_mischief · · Score: 1

    If I'm somewhere that I'm thinking about Yelp and I see a bug, you can be sure I'll post about it.

  9. look up Botto bistro by Anonymous Coward · · Score: 0

    For those who don't know the story, they've been trolling Yelp for years..