Crowdsourcing from Hackers: Strategic Coopetition and Governance in Bug Bounty Programs
References
- (2023) Bug {hunters’} perspectives on the challenges and benefits of the bug bounty ecosystem. Proc. 32nd USENIX Security Sympos. (USENIX Association, Anaheim, CA), 2275–2291.Google Scholar
- (2017) Optimal award scheme in innovation tournaments. Oper. Res. 65(3):693–702.Link, Google Scholar
- (2006) The economics of information security. Science 314(5799):610–613.Crossref, Google Scholar
- (2020) Six years of the GitHub security bug bounty programs. Accessed March 29, 2020, https://github.blog/2020-03-25-six-years-of-the-github-security-bug-bounty-program/.Google Scholar
- (2013) Sanctions, perceptions, and crime: Implications for criminal deterrence. J. Quant. Criminology 29(1):67–101.Crossref, Google Scholar
- Apple (2019) Apple security bounty. Accessed June 29, 2022, https://developer.apple.com/security-bounty/.Google Scholar
- (2006) Does information security attack frequency increase with vulnerability disclosure? An empirical analysis. Inform. Systems Frontiers 8(5):350–362.Crossref, Google Scholar
- A. S. Watson Group (2020) A.S. Watson group bug bounty program. Accessed May 7, 2022, https://hackerone.com/watson_group?type=team.Google Scholar
- (2006) Network software security and user incentives. Management Sci. 52(11):1703–1720.Link, Google Scholar
- (2011) Who should be responsible for software security? A comparative analysis of liability policies in network environments. Management Sci. 57(5):934–959.Link, Google Scholar
- (2022) Economics of ransomware: Risk interdependence and large-scale attacks. Management Sci. 68(12):8979–9002. Link, Google Scholar
- (2014) Dynamic competition in IT security: A differential games approach. Inform. Systems Frontiers 16(4):643–661.Crossref, Google Scholar
- (2003) The strategic equivalence of rent-seeking, innovation, and patent-race games. Games Econom. Behav. 44(2):217–226.Crossref, Google Scholar
- (1968) Crime and punishment: An economic approach. J. Polit. Econom. 76(2):169–217. Crossref, Google Scholar
- (2011) Incentives and problem uncertainty in innovation contests: An empirical analysis. Management Sci. 57(5):843–863.Link, Google Scholar
- (2015) Coopetition: A systematic review, synthesis, and future research directions. Rev. Managerial Sci. 9(3):577–601.Crossref, Google Scholar
- (2011) Co-Opetition (Crown Currency, New York).Google Scholar
- (2009) Configuration of and interaction between information security technologies: The case of firewalls and intrusion detection systems. Inform. Systems Res. 20(2):198–217.Link, Google Scholar
- (2014) Outsourcing information security: Contracting issues and security implications. Management Sci. 60(3):638–657.Link, Google Scholar
- (2017) Criminal deterrence: A review of the literature. J. Econom. Literature 55(1):5–48.Crossref, Google Scholar
- (2019) Optimal crowdsourcing contests. Games Econom. Behav. 113:80–96.Crossref, Google Scholar
- (2005) Asymmetric contests with general technologies. Econom. Theory 26:923–946.Crossref, Google Scholar
- (2009) Risks and benefits of signaling information system characteristics to strategic attackers. J. Management Inform. Systems 26(3):241–274.Crossref, Google Scholar
- (2021) Bug bounty programs in 2021: High payouts, higher stakes. Accessed May 7, 2022, https://www.techtarget.com/searchsecurity/news/252509175/Bug-bounty-programs-in-2021-High-payouts-higher-stakes.Google Scholar
- (1980) Uncertainty, industrial structure, and the speed of R&D. Bell J. Econom. 11(1):1–28.Crossref, Google Scholar
- (2022) Zoom’s bug bounty program: 2021 in review. Accessed May 29, 2022, https://blog.zoom.us/zoom-bug-bounty-program-2021/.Google Scholar
- (2022) What happens when bug bounties don’t work? Accessed June 7, 2022, https://vulcan.io/blog/what-happens-when-bug-bounties-dont-work/.Google Scholar
- (2010) Design and analysis of contracts for software outsourcing. Inform. Systems Res. 21(1):93–114.Link, Google Scholar
- (1987) Strategic behavior in contests. Amer. Econom. Rev. 77(5):891–898.Google Scholar
- (2018) The law and economics of bug bounties. Accessed March 1, 2022, https://www.usenix.org/conference/usenixsecurity18/presentation/elazari-bar.Google Scholar
- (2018) Coming in from the Cold: A Safe Harbor from the CFAA and the DMCA 1201 FOR Security Researchers (Berkman Klein Center Research Publication, Cambridge, MA), 1–43.Google Scholar
- European Commission (2019) EU bug bounty programme for open source software gives awards of up to eur 25,000. Accessed May 29, 2020, https://digital-strategy.ec.europa.eu/en/news/eu-bug-bounty-programme-open-source-software-gives-awards-eur-25000.Google Scholar
- Facebook (2022) Meta bug bounty programme info. Accessed May 7, 2022, https://business.facebook.com/whitehat.Google Scholar
- (2016) You’ll never guess which industry is now hiring hackers. Accessed May 29, 2020, https://www.monster.com/career-advice/article/banks-courting-hacker-cybersecurity-talent.Google Scholar
- (2013) An empirical study of vulnerability rewards programs. Proc. 22nd USENIX Security Sympos. (USENIX Association, Washington, DC), 273–288.Google Scholar
- (2017) Web science challenges in researching bug bounties. Proc. 2017 ACM Web Sci. Conf. (ACM, New York), 273–277.Google Scholar
- (2017) Man gets threats—Not bug bounty—After finding DJI customer data in public view. Accessed May 29, 2024, https://arstechnica.com/information-technology/2017/11/dji-left-private-keys-for-ssl-cloud-storage-in-public-view-and-exposed-customers/.Google Scholar
- (2005) The economic incentives for sharing security information. Inform. Systems Res. 16(2):186–208.Link, Google Scholar
- (2015) Security investment and information sharing under an alternative security breach probability function. Inform. Systems Frontiers 17(2):423–438.Crossref, Google Scholar
- (2007) Economics of conflict: An overview. Sandler T, Hartley K, eds. Handbook of Defense Economics, vol. 2 (Elsevier, Amsterdam), 649–709.Google Scholar
- GitHub (2022) Eight years of the GitHub security bug bounty program. Accessed May 29, 2022, https://github.blog/2022-05-23-eight-years-of-the-github-security-bug-bounty-program/.Google Scholar
- Google (2024) Google and Alphabet vulnerability reward program (VRP) rules. Accessed June 29, 2024, https://bughunters.google.com/about/rules/google-friends/6625378258649088/google-and-alphabet-vulnerability-reward-program-vrp-rules.Google Scholar
- (2002) The economics of information security investment. ACM Trans. Inform. System Security 5(4):438–457.Crossref, Google Scholar
- (1999) Hack, counterhack. Accessed October 3, 2023, https://archive.nytimes.com/www.nytimes.com/library/magazine/home/19991003mag-hackers.html.Google Scholar
- (2012) Growth and sustainability of managed security services networks: An economic perspective. MIS Quart. 36(4):1109–1130.Crossref, Google Scholar
- HackenProof (2023) HackenProof: Bug bounty programs and GDPR compliance. Accessed January 1, 2024, https://hackenproof.com/blog/industry-news/hackenproof-bug-bounty-programs-and-gdpr-compliance.Google Scholar
- HackerOne (2025) Reputation. Accessed March 1, 2026, https://docs.hackerone.com/en/articles/8369865-reputation.Google Scholar
- (2022) Are duplicates really harmful? An empirical study on bug report summarization techniques. J. Software Evolution Process 35(11):e2424.Crossref, Google Scholar
- (2011) Gray Hat Hacking: The Ethical Hacker's Handbook (McGraw-Hill, New York).Google Scholar
- (2022) Can bug bounty programs replace dedicated security testing? Accessed June 7, 2022, https://resources.infosecinstitute.com/topic/can-bug-bounty-programs-replace-dedicated-security-testing/.Google Scholar
- (2006) Income, interdependence, and substitution effects affecting incentives for security investment. J. Accounting Public Policy 25(6):629–665.Crossref, Google Scholar
- (2010) Nobody sells gold for the price of silver: Dishonesty, uncertainty and the underground economy. Tyler M, David P, Christos I, eds. Economics of Information Security and Privacy (Springer, Berlin, Heidelberg), 33–53.Crossref, Google Scholar
- (2010) The labor economics of paid crowdsourcing. Proc. 11th ACM Conf. Electronic Commerce (ACM, Cambridge, MA), 209–218.Google Scholar
- (2012) Information security outsourcing with system interdependency and mandatory security requirement. J. Management Inform. Systems 29(3):117–156.Crossref, Google Scholar
- (2017) Cybercrime deterrence and international legislation: Evidence from distributed denial of service attacks. MIS Quart. 41(2):497–523.Crossref, Google Scholar
- (2019) Bilateral liability-based contracts in information security outsourcing. Inform. Systems Res. 30(2):411–429.Link, Google Scholar
- (2022) Have I been pwned? Accessed June 21, 2022, https://haveibeenpwned.com/PwnedWebsites.Google Scholar
- (1976) Theory of the firm: Managerial behavior, agency costs, and ownership structure. J. Financial Econom. 3(4):305–360.Crossref, Google Scholar
- (2010) Marginality and problem-solving effectiveness in broadcast search. Organ. Sci. 21(5):1016–1033.Link, Google Scholar
- (2021) Winning by learning? Effect of knowledge sharing in crowdsourcing contests. Inform. Systems Res. 32(3):836–859.Link, Google Scholar
- (2005) Market for software vulnerabilities? Think again. Management Sci. 51(5):726–740.Link, Google Scholar
- (2016) Economic and policy implications of restricted patch distribution. Management Sci. 62(11):3161–3182.Link, Google Scholar
- (2001) Criminal law in cyberspace. Univ. Pennsylvania Law Rev. 149(4):1003–1114.Crossref, Google Scholar
- (2016) Deterring spammers: Impact assessment of the can spam act on email spam rates. Criminal Justice Policy Rev. 27(8):791–811.Crossref, Google Scholar
- (2013) The case for a compulsory bug bounty. Accessed January 29, 2020, https://krebsonsecurity.com/2013/12/the-case-for-a-compulsory-bug-bounty/.Google Scholar
- (2003) Interdependent security. J. Risk Uncertainty 26(2):231–249.Crossref, Google Scholar
- (2009) A review of the IT outsourcing literature: Insights for practice. J. Strategic Inform. Systems 18(3):130–146.Crossref, Google Scholar
- (2013) Contracting information security in the presence of double moral hazard. Inform. Systems Res. 24(2):295–311.Link, Google Scholar
- (2005) The economics of computer hacking. J. Law Econom. Policy 1:511.Google Scholar
- (2016) Apple hired the hackers who created the first Mac firmware virus. Accessed May 29, 2020, https://www.businessinsider.com/apple-hired-the-hackers-who-created-the-first-mac-firmware-virus-2016-2.Google Scholar
- (1990) The social value of crime. Internat. Rev. Law Econom. 10:271–284.Crossref, Google Scholar
- (2019) Protocols for checking compromised credentials. Proc. 2019 ACM SIGSAC Conf. Comput. Comm. Security (ACM, New York), 1387–1403.Google Scholar
- (2018) Optimal prize allocation in contests: The role of negative prizes. J. Econom. Theory 175:291–317.Crossref, Google Scholar
- (1979) Market structure and innovation. Quart. J. Econom. 93(3):395–410.Crossref, Google Scholar
- (2017) Given enough eyeballs, all bugs are shallow? Revisiting Eric Raymond with bug bounty programs. J. Cybersecurity 3(2):81–90.Crossref, Google Scholar
- (2016) Meet the hacker mom big companies hire for cybersecurity. Accessed May 29, 2020, https://www.nbcnews.com/tech/internet/meet-hacker-mom-big-companies-hire-cyber-security-n964291.Google Scholar
- (2024) Google VRPs in review—2025. Accessed March 29, 2026, https://bughunters.google.com/blog/google-vrps-in-review-2025.Google Scholar
- (2015) Information disclosure and the diffusion of information security attacks. Inform. Systems Res. 26(3):565–584.Link, Google Scholar
- (1984) Market segmentation, self-selection, and product line design. Marketing Sci. 3(4):288–307.Link, Google Scholar
- (2016) Vulnerability severity scoring and bounties: Why the disconnect? Proc. Second Internat. Workshop Software Anal. (ACM, New York), 8–14.Google Scholar
- (2026) Curl creator who called mythos a “PR stunt” says AI will not take human jobs, but might kill bug bounties. Accessed June 5, 2026, https://cybernews.com/security/curl-bug-bounty-ai-security-reports-daniel-stenberg/.Google Scholar
- Oracle.com (2015) No you really cannot. Accessed January 29, 2022, https://gist.github.com/michaeldyrynda/9b5eac6c02e6089052a6.Google Scholar
- (2018) Inside Uber’s $100,000 payment to a hacker, and the fallout. Accessed January 12, 2022, https://www.nytimes.com/2018/01/12/technology/uber-hacker-payment-100000.html.Google Scholar
- (2009) Information security: Facilitating user precautions vis-à-vis enforcement against attackers. J. Management Inform. Systems 26(2):97–121.Crossref, Google Scholar
- (2008) The deterrent and displacement effects of information security enforcement: International evidence. J. Management Inform. Systems 25(2):125–144.Crossref, Google Scholar
- (2020) Bug bounty platforms buy researcher silence, violate labor laws, critics say. Accessed June 7 2022, https://www.csoonline.com/article/3535888/bug-bounty-platforms-buy-researcher-silence-violate-labor-laws-critics-say.html.Google Scholar
- (2009) Fighting cybercrime: Legislation in China. Internat. J. Electronic Security Digital Forensics 2(2):219–227.Crossref, Google Scholar
- (1994) Strategic outsourcing. Sloan Management Rev. 35(4):43–55.Google Scholar
- (2009) Choice and chance: A conceptual model of paths to information security compromise. Inform. Systems Res. 20(1):121–139.Link, Google Scholar
- (2012) Are markets for vulnerabilities effective? MIS Quart. 36(1):43–64.Crossref, Google Scholar
- (2012) The economics of spam. J. Econom. Perspect. 26(3):87–110.Crossref, Google Scholar
- (2011) Do data breach disclosure laws reduce identity theft? J. Policy Anal. Management 30(2):256–286.Crossref, Google Scholar
- (2002) How to buy better testing using competition to get the most security and robustness for your dollar. Internat. Conf. Infrastructure Security (Springer, Berlin, Heidelberg), 73–87.Google Scholar
- (1973) Job market signaling. Quart. J. Econom. 87(3):355–374.Crossref, Google Scholar
- (2020) Groups promote computer misuse act update to enable security research. Accessed May 7, 2021, https://www.csoonline.com/article/3566140/groups-promote-computer-misuse-act-update-to-enable-security-research.html.Google Scholar
- (1997) On the existence and uniqueness of pure Nash equilibrium in rent-seeking games. Games Econom. Behav. 18(1):135–140.Crossref, Google Scholar
- (2008) Innovation contests, open innovation, and multiagent problem solving. Management Sci. 54(9):1529–1543.Link, Google Scholar
- (2008) Terrorizing the technological neighborhood watch: The alienation and deterrence of the white hats under the CFAA. Florida State Univ. Law Rev. 36:537–585.Google Scholar
- (1980) Efficient rent seeking. Buchanan J, Tollison R, Tullock G, eds. Toward a Theory of the Rent-Seeking Society (Texas A&M University Press, College Station, TX), 97–112.Google Scholar
- U.S. Department of Defense (2018) Department of defense expands ‘hack the pentagon’ crowdsourced digital defense program. Accessed May 7, 2022, https://www.defense.gov/News/Releases/Release/Article/1671231/department-of-defense-expands-hack-the-pentagon-crowdsourced-digital-defense-pr/.Google Scholar
- Virginia Tech IT Security Office (2021) The Virginia Tech bug bounty program. Accessed May 7, 2022, https://bugbounty.aws.cloud.iso.vt.edu/.Google Scholar
- Wikipedia (2022) List of data breaches. Accessed June 21, 2022, https://en.wikipedia.org/wiki/List_of_data_breaches.Google Scholar
- (2020) U.S. Army hacked by 52 hackers in five weeks. Accessed March 29, 2020, https://www.forbes.com/sites/daveywinder/2020/01/16/us-army-hacked-by-52-hackers-in-five-weeksheres-why/#6fd351e81669.Google Scholar
- Wired (2000) Apache site defaced. Accessed January 29, 2020, https://www.wired.com/2000/05/apache-site-defaced/.Google Scholar
- (2020) HINDBR: Heterogeneous information network based duplicate bug report prediction. 2020 IEEE 31st Internat. Sympos. Software Reliability Engrg. (IEEE, Coimbra, Portugal), 195–206.Google Scholar
- (2019) See no evil, hear no evil? Dissecting the impact of online hacker forums. MIS Quart. 43(1):73–95.Crossref, Google Scholar
- (2024) How to make my bug bounty cost-effective? A game-theoretical model. Inform. Systems Res. 36(2):1031–1053.Google Scholar
- (2023) Duplicate bug report detection: How far are we? ACM Trans. Software Engrg. Methodology 32(4):1–32.Google Scholar
- (2015) An empirical study of web vulnerability discovery ecosystems. Proc. 22nd ACM SIGSAC Conf. Comput. Comm. Security (ACM, New York), 1105–1117.Google Scholar
- (2017) Devising effective policies for bug-bounty platforms and security vulnerability discovery. J. Inform. Policy 7:372–418.Crossref, Google Scholar

