What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Pinterest began offering cash rewards for vulnerability reports in March 2015, replacing a program that had offered Bugcrowd Kudos points and possible merchandise. Today, Pinterest directs researchers to report through Bugcrowd, but its current responsible disclosure statement does not publish bounty amounts or detailed scope terms. The 2015 figures and asset list should not be treated as current rules.

What changed when Pinterest began paying researchers?

Pinterest launched its Bugcrowd program in May 2014 with Kudos points and the possibility of a T-shirt, according to SecurityWeek’s March 18, 2015 report. On March 18, 2015, SecurityWeek reported that Pinterest had begun offering monetary rewards for vulnerabilities found in its domains and mobile apps.

The announcement was connected to Pinterest’s migration to HTTPS. SecurityWeek quoted Paul Moreno, then identified as Pinterest’s security engineering lead for the Cloud team, saying the company had been hesitant to start a paid program while it knew of vulnerabilities associated with operating only over HTTP. That is historical context for the program’s timing; HTTPS is an important security measure, not a guarantee that a service has no vulnerabilities.

What were the 2015 reward amounts and scope?

SecurityWeek reported minimum rewards ranging from $25 to $200, depending on the bug type. Its examples included $200 minimums for remote code execution and authentication bypass, and $100 minimums for cross-site request forgery (CSRF) and cross-site scripting (XSS). These are figures reported in 2015, not verified current bounty amounts.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The same article described the then-current scope as including pinterest.com, business.pinterest.com, help.pinterest.com, developers.pinterest.com, api.pinterest.com, about.pinterest.com, ads.pinterest.com, and Pinterest’s Android and iOS apps. It also listed exclusions, including self-XSS, logout CSRF, certain open redirects, login and password-reset brute force, missing HTTP security headers, and attacks requiring physical access. None of these historical scope details should be assumed to apply today.

What do we know about the program since then?

In a November 13, 2018 retrospective, Pinterest Engineering said the company had been paying monetary rewards since 2015 and working with Bugcrowd. Product Security Tech Lead Devin Lundberg described the program as covering Pinterest subdomains, mobile apps, browser extensions, and open-source projects. Those categories document the program at the time of the retrospective; they do not establish today’s precise scope.

Lundberg reported that by 2018 Pinterest had awarded more than $35,000 for more than 150 valid, non-duplicate submissions, with a highest single reward of $2,500. These are historical totals as of that article, not current program statistics. Read the Pinterest Engineering retrospective.

How do you report a Pinterest vulnerability now?

Pinterest’s current responsible disclosure statement says the program is managed through Bugcrowd. It directs prospective participants to visit Pinterest’s program there and sign up as testers. Participants must accept Pinterest’s Terms of Service, and researchers should submit vulnerability reports through Bugcrowd to be eligible for rewards.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Open Pinterest’s Bugcrowd engagement at https://bugcrowd.com/pinterest.
  2. Review the live engagement brief and sign up as a tester through Bugcrowd.
  3. Read and accept Pinterest’s Terms of Service and follow the current brief’s reporting instructions.
  4. Submit the vulnerability through Bugcrowd if seeking reward eligibility.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Does Pinterest still pay, and how much?

Pinterest’s current policy confirms a reward-eligible reporting route, but the policy text does not state payout amounts. The Bugcrowd engagement page available for review did not expose readable bounty terms. As a result, a current reward range, exact scope, exclusions, response-time commitments, and eligibility limits cannot be confirmed from those pages. Check the live engagement brief and applicable Pinterest terms before testing or submitting a report; do not rely on the 2015 minimums or the 2018 payout statistics as current terms.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.