请输入您要查询的百科知识:

 

词条 HackerOne
释义

  1. History

  2. Funding

  3. U.S. Department of Defense Programs

  4. Events and Live Hacking

  5. Locations

  6. References

  7. Further reading

  8. External links

{{infobox company
| name = HackerOne
| type = Private
| industry = Cybersecurity
| founded = 2012
| founders = Michiel Prins, Jobert Abma, Alex Rice and Merijn Terheggen
| hq_location = San Francisco, California
| key_people = Mårten Mickos (CEO)
|website = {{URL|https://hackerone.com}}
}}HackerOne is a vulnerability coordination and bug bounty platform that connects businesses with cybersecurity researchers.[1] It was one of the first companies, along with Synack and Bugcrowd, to embrace and utilize crowd-sourced security and cybersecurity researchers as linchpins of its business model; it is the largest cybersecurity firm of its kind.[1] As of July 2018, HackerOne's network consisted of approximately 200,000 researchers, had resolved 72,000 vulnerabilities across over 1,000 customer programs, and had paid $31 million in bounties.[3]

History

In 2011, Dutch hackers Jobert Abma and Michiel Prins attempted to find security vulnerabilities in 100 prominent high-tech companies. They discovered flaws in all of the companies, including Facebook, Google, Apple, Microsoft, and Twitter. Dubbing their efforts the "Hack 100", Abma and Prins contacted the at-risk firms. While many firms ignored their disclosure attempts, the COO of Facebook, Sheryl Sandberg, gave the warning to their head of product security, Alex Rice. Rice, Abma and Prins connected, and together with Merijn Terheggen founded HackerOne in 2012.[1] In November 2015, Terheggen stepped down from his role as CEO and was replaced by Marten Mickos.[2]

In November 2013, the company hosted a program encouraging the discovery and responsible disclosure of software bugs. Microsoft and Facebook funded the initiative, known as the Internet Bug Bounty project.[3] By June 2015, HackerOne's bug bounty platform had identified approximately 10,000 vulnerabilities and paid researchers over $1 million in bounties.[4] In September 2015, the company launched a Vulnerability Coordination Maturity Model, which then-policy chief Katie Moussouris described as “an important effort from HackerOne to codify some reasonable minimum standards on how organizations handle incoming, unsolicited vulnerability reports.”[5] In April 2017, the company announced 240% year-over-year customer growth in Europe, and the subsequent opening of additional European offices to serve increasing customer demand.[6]

Funding

In May 2014, HackerOne received $9 million (USD) in Series A funding from venture capital firm Benchmark.[7][8] A $25 million Series B round was led by New Enterprise Associates.[9] Angel investors include Salesforce CEO Marc Benioff, Digital Sky Technologies founder Yuri Milner, Dropbox chief executive Drew Houston and Yelp CEO Jeremy Stoppelman.[4][10] A Series C round led by Dragoneer Investment Group netted $40 million in February 2017 for a total of $74 million in investments to date.[11] In April 2017, European-based venture capital fund EQT Ventures invested in the $40 million Series C funding round.[6]

U.S. Department of Defense Programs

In March 2016, the U.S. Department of Defense (DoD) launched an initiative dubbed "Hack the Pentagon" using the HackerOne platform.[12][13] The 24-day program resulted in the discovery and mitigation of 138 vulnerabilities in DoD websites, with over $70,000 (USD) in bounties paid to participating researchers.[14]

In October of the same year, DoD developed a Vulnerability Disclosure Policy (VDP), the first of its kind created for the U.S. government. The policy outlines the conditions under which cybersecurity researchers may legally explore front-facing programs for security vulnerabilities. The first use of the VDP launched as part of the "Hack the Army" initiative, which was also the first time this branch of the U.S. military welcomed hackers to find and report security flaws in its systems.[15][16]

The Hack the Army initiative resulted in 118 valid vulnerability reports; 371 participants, including 25 government workers and 17 military personnel, took part. Approximately $100,000 (USD) in total was awarded to participating researchers.[17]

In May 2017, DoD extended the program to "Hack the Air Force". This program led to the discovery of 207 vulnerabilities, netting more than $130,000 (USD) in paid bounties. As of the end of 2017, DoD has learned of and fixed thousands of vulnerabilities through their vulnerability disclosure initiatives.[18]

Events and Live Hacking

In February 2017, HackerOne sponsored an invitation-only hackathon, gathering security researchers from around the world to hack e-commerce sites Airbnb and Shopify for vulnerabilities.[19] This was the second such hackathon, with the company hosting one in Las Vegas in August 2016 during the Black Hat Security Conference.[20] Throughout 2017 and so far in 2018, HackerOne hosted seven Live Hacking events in cities across the US and Europe.[21] Over $1 million in bounty cash has been awarded at these events, with Oath paying over $400,000 in bounties during a single event in San Francisco, CA in April 2018.[22]

In October 2017, HackerOne hosted their first conference, called Security@ San Francisco. The 200-attendee event included speakers from DoD, General Motors and Uber and also featured talks from hackers.[23]

Locations

HackerOne is headquartered in San Francisco. The company maintains a development office in Groningen, Netherlands.[24] In April 2017, the company announced the addition of offices in the UK and Germany.[6]

References

1. ^{{Cite news|url=https://www.nytimes.com/2015/06/08/technology/hackerone-connects-hackers-with-companies-and-hopes-for-a-win-win.html?_r=0|title=HackerOne connects hackers with companies and hopes for a win-win.|last=|first=|date=June 7, 2015|work=The New York Times|access-date=October 28, 2015|archive-url=|archive-date=|dead-url=}}
2. ^{{Cite web|url=http://fortune.com/2015/11/11/serial-ceo-marten-at-hackerone/|title=Serial CEO Marten MIckos takes the reins at HackerOne|website=Fortune|access-date=2017-03-15}}
3. ^{{Cite news|url=https://www.bloomberg.com/news/articles/2015-03-12/ethical-hackers-booming-job-market|title=The Big Business of Smashing Bugs|date=2015-03-12|work=Bloomberg.com|access-date=2017-03-15}}
4. ^{{Cite web|url=http://fortune.com/2015/06/24/hackerone-raises-series-b/|title=HackerOne, a computer bug bounty firm, raises $25 million in Series B|website=Fortune|access-date=2017-03-15}}
5. ^{{Cite news|url=https://www.hackerone.com/sites/default/files/2018-03/HackerOne_Press_Kit.pdf|title=HackerOne Press Kit & FAQ|last=HackerOne|first=|date=March 2018|work=|access-date=2018-07-27|language=en}}
6. ^{{Cite news|url=http://www.businesswire.com/news/home/20170410005453/en/HackerOne-Strengthens-Presence-Europe-Growing-Demand-Hacker-Powered|title=HackerOne Strengthens Presence in Europe Amid Growing Demand for Hacker-Powered Security|last=|first=|date=2017-04-10|work=BusinessWire|access-date=2018-07-27|archive-url=|archive-date=|dead-url=}}
7. ^{{Cite web|url=https://techcrunch.com/2014/05/28/hackerone-get-9m-in-series-a-funding-to-build-bug-tracking-bounty-programs/|title=HackerOne Get $9M In Series A Funding To Build Bug Tracking Bounty Programs|last=Miller|first=Ron|website=TechCrunch|access-date=2017-03-15}}
8. ^{{Cite web|url=https://gigaom.com/2014/05/28/hackerone-lands-9-million-to-aid-in-its-bug-disclosure-program/|title=HackerOne lands $9 million to aid in its bug-disclosure program|last=Vanian|first=Jonathan|date=2014-05-28|website=gigaom.com|language=en-US|access-date=2017-03-15}}
9. ^{{Cite news|url=http://www.zdnet.com/article/hackerone-raises-25-million-in-vulnerability-management-push/|title=HackerOne raises $25 million in vulnerability management push {{!}} ZDNet|last=Osborne|first=Charlie|work=ZDNet|access-date=2017-03-15|language=en}}
10. ^{{Cite web|url=https://venturebeat.com/2015/06/24/hackerone-raises-25m-to-make-the-internet-safer-via-bug-bounty-programs/|title=HackerOne raises $25M to make the Internet safer via bug bounty programs|website=VentureBeat|access-date=2017-03-15}}
11. ^{{Cite web|url=http://www.businesswire.com/news/home/20170208005334/en/HackerOne-Raises-40-Million-Internet-Safer|title=HackerOne Raises $40 Million to Make the Internet Safer for Everyone|website=www.businesswire.com|language=en|access-date=2017-03-15}}
12. ^{{Cite news|url=https://www.defense.gov/News/Article/Article/684616/dod-invites-vetted-specialists-to-hack-the-pentagon|title=DoD Invites Vetted Specialists to ‘Hack’ the Pentagon|work=U.S. DEPARTMENT OF DEFENSE|access-date=2017-03-15|language=en-US}}
13. ^{{Cite news|url=https://www.defense.gov/News/Article/Article/710033/hack-the-pentagon-pilot-program-opens-for-registration|title=’Hack the Pentagon’ Pilot Program Opens for Registration|work=U.S. DEPARTMENT OF DEFENSE|access-date=2017-03-15|language=en-US}}
14. ^{{Cite web|url=https://techcrunch.com/2016/06/17/department-of-defense-expanding-hack-the-pentagon-program/|title=Department of Defense expanding Hack the Pentagon program|last=Conger|first=Kate|website=TechCrunch|access-date=2017-03-15}}
15. ^{{Cite news|url=http://www.zdnet.com/article/dod-hackerone-kick-off-hack-the-army-bug-bounty-challenge/|title=DoD, HackerOne kick off Hack the Army bug bounty challenge {{!}} ZDNet|last=Osborne|first=Charlie|work=ZDNet|access-date=2017-03-15|language=en}}
16. ^{{Cite news|url=http://federalnewsradio.com/dod-reporters-notebook-jared-serbu/2017/01/armys-first-bug-bounty-uncovers-entry-points-sensitive-dod-networks/|title=Army's first bug bounty uncovers entry point to sensitive DoD network|date=2017-01-24|work=FederalNewsRadio.com|access-date=2017-03-15|language=en-US}}
17. ^{{Cite news|url=http://www.executivegov.com/2017/01/hackers-found-118-valid-vulnerabilities-during-army-bug-bounty-program/|title=Hackers Found 118 Valid Vulnerabilities During Army Bug Bounty Program - Executive Gov|work=Executive Gov|access-date=2017-03-15|language=en-US}}
18. ^{{Cite news|url=https://www.wired.com/story/hack-the-pentagon-bug-bounty-results/|title=The Pentagon Opened up to Hackers--And Fixed Thousands of Bugs|last=Newman|first=Lily Hay|date=2017-11-10|work=Wired|access-date=2018-07-27}}
19. ^{{Cite news|url=http://www.sfgate.com/business/article/Ethical-hackers-work-with-Airbnb-Shopify-10929609.php|title=‘Ethical hackers’ work with Airbnb, Shopify|work=SFGate|access-date=2017-03-15}}
20. ^{{Citation|last=HackerOne|title=h1-702 Las Vegas Hackathon|date=2017-02-10|url=https://www.youtube.com/watch?v=LVOXjzd-M7U|accessdate=2017-03-15}}
21. ^{{Cite web|url=https://www.hackerone.com/live-hacking|title=Live Hacking|last=HackerOne|first=|date=2018|website=HackerOne|archive-url=|archive-date=|dead-url=|access-date=}}
22. ^{{Cite web|url=https://www.oath.com/2018/04/20/we-invited-40-of-the-world-s-best-security-researchers-to-hack-o/|title=We invited 40 of the world’s best security researchers to hack our products. Here’s what happened|last=Nims|first=Chris|date=2018-04-20|website=Oath|archive-url=|archive-date=|dead-url=|access-date=2018-07-27}}
23. ^{{Cite web|url=https://www.hackerone.com/blog/Introducing-Security-at-San-Francisco|title=Introducing Security@ San Francisco!|last=|first=|date=2017-10-17|website=HackerOne|archive-url=|archive-date=|dead-url=|access-date=2018-07-27}}
24. ^{{Cite web|url=https://www.foundedingroningen.com/news/hackerone-founded-in-groningen-kicking-ass-in-san-francisco|title=HackerOne: Founded in Groningen, kicking ass in San Francisco|last=Kootstra|first=Richard|date=2016-02-14|website=Founded in Groningen|archive-url=|archive-date=|dead-url=|access-date=2018-07-27}}

Further reading

  • [https://bits.blogs.nytimes.com/2015/10/14/hacking-for-security-and-getting-paid-for-it/?_r=0 Hacking For Security and Getting Paid For It]. New York Times. October 14, 2015.
  • This Hacker Makes An Extra $100,000 A Year As A Bug Bounty Hunter. Business Insider. May 21, 2016.
  • [https://www.bna.com/views-bug-bounty-n57982072941/ Views on Bug Bounty Programs and Ethical Hacking From HackerOne Inc. Chief Executive Officer Marten Mickos.] Bloomberg BNA. May 25, 2016.
  • Twitter Pays $322,420 to Bug Hunters Under ‘HackerOne’ Program. Indian Express Tech IE. May 28, 2016.
  • How HackerOne’s Famous New CEO is Helping Teen Hackers Become Agents of Good, Not Evil. Business Insider. July 1, 2016.
  • [https://www.cnbc.com/2016/10/20/hackerone-ceo-every-computer-system-is-subject-to-vulnerabilities.html HackerOne CEO: Every Computer is Subject to Vulnerabilities.] CNBC. October 20, 2016.
  • The Technologist Convincing the Pentagon to Love Hackers. Christian Science Monitor. October 21, 2016.
  • A Look At The Top HackerOne Bounties of 2016. ZDNet. December 6, 2016.
  • [https://techcrunch.com/2017/01/19/hacking-the-army/ Hacking The Army.] TechCrunch. January 19, 2017.
  • [https://www.scmagazine.com/ethical-hackers-a-question-of-choice/article/634394/ Ethical Hackers: A Question of Choice.] SC Magazine. January 27, 2017.

External links

  • [https://www.hackerone.com Company Website]
  • [https://www.crunchbase.com/organization/hackerone#/entity Company Profile: Crunchbase]
  • [https://www.bloomberg.com/profiles/companies/1291554D:US-hackerone-inc Company Profile: Bloomberg]
  • BugSheet Bug Bounties & Disclosure Programs (Community Curated)

3 : Companies based in San Francisco|2012 establishments in California|Computer security companies

随便看

 

开放百科全书收录14589846条英语、德语、日语等多语种百科知识,基本涵盖了大多数领域的百科知识,是一部内容自由、开放的电子版国际百科全书。

 

Copyright © 2023 OENC.NET All Rights Reserved
京ICP备2021023879号 更新时间:2024/9/23 10:30:17