Two months after United Airlines launched a bug-bounty program to reward researchers who report flaws in the company's web site and apps, security researcher Jordan Wiens received 1 million air miles in the first reward given. He had submitted details of a remote-code execution flaw in the airline's web site, and the deposit showed up in his mileage account.

United is the first airline to launch a bug bounty program, announcing it in May 2015 after harsh criticism for banning a security researcher from one of its flights. The payout structure is unusual: most vendor bounty programs pay cash that varies between $500 and $250,000, but United pays only air miles. The cash value of Wiens' million miles was about $25,000.

The miles scale with the bug. Cross-site scripting earns 50,000 miles, an authentication bypass can earn 250,000, and remote-code execution flaws — which let an attacker remotely run whatever malicious code they want — earn the top payout. Wiens, who had never submitted to a bug-bounty program before, said he submitted two bugs he was pretty sure were remote code execution but thought were 'lame', expecting 50,000 miles or something smaller; after confirming he was a US citizen and that his research was done in the US, United told him to check his mileage account.

The program turned a hostile relationship into a pipeline: it was announced right after United was criticized for banning a researcher from a flight.

Miles are an asset United issues itself, so a headline reward worth about $25,000 costs no cash — while rival programs pay out up to $250,000 per bug.

Pricing severity in miles — 50,000, 250,000, top award for remote code execution — gives researchers a public exchange rate for which bugs are worth chasing.

It worked on first contact: a first-time bounty submitter found a remote-code execution flaw and was paid the program's first reward within two months of launch.

A bounty's headline value and its cost to the payer need not match: pay in an asset you mint yourself, keep the reward big enough to matter, and keep cash out of the deal.

Wiens' million-mile award was the program's first reward, given about two months after the May 2015 launch. United required submitters to confirm eligibility — US citizenship and research done in the US — before paying out.

FOLLOW THE EVIDENCE

The sources

  1. United Airlines Pays Man a Million Miles for Reporting Bug wired.com