Sony Pixel Power calrec Sony

6 Frequently Asked Questions About Spotify's Bug Bounty Program

13/09/2019

Streaming, and Spotify for that matter, couldn't have been made possible without the accessibility and connectivity of the Internet. Unfortunately, with that openness and interconnectedness, came malicious attackers who look to exploit weaknesses in web sites and applications.

At Spotify, we're committed to protecting our information, as well as yours. So two years ago we began using the HackerOne platform for our bug bounty program. Now, we're looking back on successes and learnings that will continue to help improve the program at Spotify.

Want to learn more? We've broken it down into six frequently asked questions.

1. First off, what is a bug bounty program? There are ethical and responsible security researchers who discover weaknesses via the same tactics and tools used by hackers. They report these weaknesses to site owners, so that they can be fixed before others can use them for malicious purposes. Bug bounty programs exist to make it easier for security researchers to report these weaknesses to site owners. As a token of gratitude, the site owners often reward money or swag to the researchers for their efforts.

2. When and why did Spotify start a bug bounty program? Our Security team launched its bug bounty program in 2015, when we were a very small team that occasionally received vulnerability reports from researchers responsibly disclosing bugs. Although we didn't receive a huge number of reports, it was clear that managing them by hand, primarily through email, would prove difficult. During that time, we had been rewarding reports with any swag we happened to have on hand, or giving them credit on our wall of fame at https://www.spotify.com/bounty/. However, because this work and reporting was so crucial, we wanted to start giving cash for bug submissions.

In May 2017, we moved our bug bounty program onto HackerOne, a leading cybersecurity bug bounty platform, to take advantage of their platform and managed services. We now accept bug bounty reports at https://hackerone.com/spotify. From there, the HackerOne team reviews the report for validity and severity, then loops in our Spotify Security team. Then, we're able to work together to find a resolution and reward the security researcher who found the bug in the first place.

3. What are some of the benefits of using HackerOne? Since we started using the HackerOne platform and managed services, we've received over 365 valid and actionable reports and rewarded over $120,000 to security researchers for their efforts.

4. What sort of problems have been reported? We receive the largest amount of reports on our most visible websites, www.spotify.com and community.spotify.com, but also receive reports on our mobile applications, desktop applications, and other apps and software.

One other area where we face challenges is with partner development. The reports we get here are for sites that Spotify has contracted to have built, or companies that Spotify has acquired that didn't have the benefit of being developed with the same security protocols in place.

5. Why is finding these vulnerabilities such a big deal? If the vulnerabilities mentioned above were to be discovered by a malicious actor, our websites or apps could be attacked, thus harming the brand and reputation of Spotify. Or, the credentials could be used for lateral movement or in a phishing attack. None of this is good for us or our users.

6. So what's the next step for security at Spotify? As mentioned, a lot of reports come regarding sites developed by our partner developers. So to help them, we're developing something we call the Global Preferred Production Partner Program. It's a security-focused set of standards and runtime environments for Partner Developers outside of Spotify. It also includes a set of expectations for vendors that help us ensure we can rapidly and effectively respond and correct vulnerabilities that are reported to us through the bug bounty program.

So far, working with HackerOne has raised security awareness within our engineering organization, exposed weaknesses in our security posture, and helped us better understand our attack surface. Even if you have no experience in bug hunting, check out our program page at https://hackerone.com/spotify. We think there are always opportunities to make our security stronger.
LINK: https://newsroom.spotify.com/2019-09-13/6-frequently-asked-questions-a...
See more stories from spotify

Most recent headlines

09/11/2025

Dalet Unveils Agentic AI Media Workflows at IBC2025

Dalet today announced a transformative leap forward for media operations: Agentic Artificial Intelligence (AI) that unifies the Dalet ecosystem under one natura...

24/10/2025

Spectrum Reach Has Deployed More Than 15,000 AI-Powered Ad Campaigns

NEW YORK Charters Spectrum Reach has announced that its clients have used Waymark's AI-driven ad creation platform to create more than 15,000 ads since Spec...

24/10/2025

Avid Releases Pro Tools 2025.10

BURLINGTON, Mass. Avid has today announced the release of Pro Tools 2025.10, a feature-rich update that the company said offers notable advances in immersive mu...

24/10/2025

Comcast Advertising Unveils Programmatic Solution for Linear TV

NEW YORK In a major change for the ad industry, Comcast Advertising will unveil technology that enables agencies and brands to buy targetable, biddable ads on l...

24/10/2025

ATSC Expands Its Influence with Growing International Ties

WASHINGTON The ATSC broadcast standards group has outlined a growing list of international activities that the group said is expanding its influence and solidif...

23/10/2025

Unlocking Character: Sportcast on Executing the Bundesliga and Bundesliga 2 New Season Production

Unlocking character: Sportcast on executing the Bundesliga and Bundesliga 2 new ...

23/10/2025

Clear Coordination: Juggling the New Bundesliga Rights Cycle Requirements and Pushing Innovation Forward at Sportcast

Clear coordination: Juggling the new Bundesliga rights cycle requirements and pu...

23/10/2025

Analysis: Is Piracy Just the Cost of Doing Business?

Analysis: Is piracy just the cost of doing business? By Callum McCarthy, Editor-at-Large Tuesday, October 21, 2025 - 09:58 Print This Story It's high ...

23/10/2025

ESPN's Adam Whitlock on Driving Real-World Innovation Across the Video-Transmission Industry

ESPN's Adam Whitlock on Driving Real-World Innovation Across the Video-Trans...

23/10/2025

SVG TranSPORT 2025 Unites 300+ Industry Leaders in New York for Deep Dive Into Live Transmission Technology

SVG TranSPORT 2025 Unites 300+ Industry Leaders in New York for Deep Dive Into L...

23/10/2025

NBA Tip-Off: League Starts Season With Two New Broadcast Partners, In-House NBA TV/NBA App Ops

NBA Tip-Off: League Starts Season With Two New Broadcast Partners, In-House NBA ...

23/10/2025

NFL Deepens Business Partnership with EA Sports; More Madden Casts to Come?

NFL Deepens Business Partnership with EA Sports; More Madden Casts to Come?EA Sports will remain the exclusive producer and distributor of Madden NFL video game...

23/10/2025

NFL Moves Pro Bowl Games Indoors and to Super Bowl Week; Leans Into a Made-for-TV Presentation

NFL Moves Pro Bowl Games Indoors and to Super Bowl Week; Leans Into a Made-for-T...

23/10/2025

Together in Time: Alan Domnguez on the Common Themes in his Films and Sundance Institute's Support

By Alan Dominguez Recently I have been thinking about the intersection of two e...

23/10/2025

Coexistence, My Ass! Dares Peacemaking to Not Be So Serious

(L-R) Amber Fares and Noam Shuster Eliassi attend the 2025 Sundance Film Festival premiere of Coexistence, My Ass! at the Egyptian Theatre on January 26, 2025...

23/10/2025

A Force Multiplier for High-Frequency Communications: The L3Harris ARGUS-HF

The new solution is industry's first multi-channel receiver available for L3Harris's resilient tactical high-frequency data waveforms....

23/10/2025

Survey: Americans Concerned' About AI's Impact on Journalism

NEW YORK During a high-profile session at NAB Show New York, new survey data was shared that revealed significant public concern over artificial intelligence (A...

23/10/2025

Fox Weather Taps T-Mobile's SuperMobile for Extreme Weather Coverage

BELLEVUE, Wash. and NEW YORK Fox Weather has tapped T-Mobile as its preferred communications provider and said all of its reporters will be equipped with SuperM...

23/10/2025

Mike Wright Joins Lawo as VP, Sales, North America

RASTATT, Germany Broadcast and media workflow technology vendor Lawo has tapped Mike Wright as VP of sales, North America....

23/10/2025

European Broadcaster ARTE Taps Grass Valley for IP Transition

MONTREAL European cultural broadcaster ARTE has selected Grass Valley LDX 135 cameras and Creative Grading solution as part of its move from SDI/1080i to a nati...

23/10/2025

Scripps Names Daniel Parsons Chief Information Security Officer

CINCINNATI The E.W. Scripps Company has named Daniel Parsons as its new chief information security officer, effective Oct. 20....

23/10/2025

WWTV Completes IP Studio Upgrade

ALAMEDA, Calif. Northern Michigan broadcaster WWTV recently completed a major IP-based upgrade that connects its new Traverse City studio with its control room ...

23/10/2025

Verizon Fios TV, Nexstar Blackout Looms as Contract Ends on Oct. 24

A deadline is looming for a new carriage deal between Verizon's Fios TV and Nexstar, with both Verizon and the pay TV-backed American Television Alliance bl...

23/10/2025

Survey: Americans 'Concerned' About AI's Impact on Journalism

NEW YORK During a high-profile session at NAB Show New York, new survey data was shared that revealed significant public concern over artificial intelligence (A...

23/10/2025

Fox Weather Taps T-Mobile's Supermobile for Extreme-Weather Coverage

BELLEVUE, Wash. and NEW YORK Fox Weather has tapped T-Mobile has as its preferred communications provider and announced that all Fox Weather reporters are being...

23/10/2025

PBS Taps Amazon Bedrock to Improve Search on Digital Platforms

PBS will use generative AI from Amazon Web Services to provide enhanced search results to viewers on the PBS App and PBS LearningMedia platforms, the network an...

23/10/2025

Actor Jessica Barden joins Becoming Victoria Wood - U&GOLD's feature-length documentary celebrating the life of Victoria Wood

The 90-minute film is produced by Rogan Scotland, part of BAFTA-winning Rogan Pr...

23/10/2025

The Resurrected' Marks First Chinese-Language Series to Launch Netflix Profile Icons

Back to All News The Resurrected' Marks First Chinese-Language Series to L...

23/10/2025

RT publishes Register of External Activities for Q2/2025 (statistical summary)

RT is today publishing a statistical summary from the Register of External Activities for the second quarter of 2025. The RT Register of External Activities ...

23/10/2025

THE BOYS ARE BACK IN TOWN THE 2 JOHNNIES LATE NIGHT LOCK IN RETURNS FOR SERIES 3

Series three of the award winning, hit comedy entertainment series The 2 Johnnies Late Night Lock In is back on your screens, celebrating the very best of all t...

23/10/2025

Fleadh Cheoil, presented by Dith S and Muireann Nic Amhlaoibh returns to RT

Performances by Michael Flatley, Andy Irvine, Cuckoo's Nest, Foster and Allen and more Friday 24 October, 8pm on RT One and RT Player Fleadh Cheoil re...

23/10/2025

Fangs Out, Frames Up: Vampire: The Masquerade - Bloodlines 2' Leads a Killer GFN Thursday

The nights grow longer and the shadows get bolder with Vampire The Masquerade: B...

22/10/2025

ITE Singapore Officially Opens Next-Generation Hybrid Learning Space with X2O Media's OneRoom

MONTR AL - October 2, 2025 - The Institute of Technical Education (ITE) last mon...

22/10/2025

Prime Video Inks Deal To Present NFL Black Friday Game Worldwide

Prime Video Inks Deal To Present NFL Black Friday Game Worldwide By SVG Staff Wednesday, October 22, 2025 - 10:06 am Print This Story | Subscribe Story ...

22/10/2025

NBA Tip-Off: ESPN Goes 1080p HDR End-to-End, Flipping HDR Switch on REMI and REMCO Shows

NBA Tip-Off: ESPN Goes 1080p HDR End-to-End, Flipping HDR Switch on REMI and REM...

22/10/2025

FloSports Empowers Division II, III Athletic Departments With Turnkey Production Suite for Livestreaming Production

FloSports Empowers Division II, III Athletic Departments With Turnkey Production...

22/10/2025

Wall Street Video Summit Debuts, Bringing Together 200 Financial Enterprise Video Executives in NYC

Wall Street Video Summit Debuts, Bringing Together 200 Financial Enterprise Vide...

22/10/2025

Dueling Pianos: International Chopin Piano Competition Is as Competitive as a Ballgame - and Has Amazing Audio

Dueling Pianos: International Chopin Piano Competition Is as Competitive as a Ba...

22/10/2025

Celebrate the Anniversaries of Shakira's Landmark Albums With Spotify-Exclusive EP and Video Special

In 1995, a young Colombian artist released an album that would change Latin pop ...

22/10/2025

SGL Carbon expands sustainable energy supply and invests in photovoltaic system at Meitingen site

Over the past few months, a photovoltaic system has been installed on a three-he...

22/10/2025

Orion Meets SLS: L3Harris Technology Ready to go to the Moon

The Orion spacecraft for NASA's Artemis II mission is stacked on the Space Launch System (SLS) rocket in High Bay 3 of the Vehicle Assembly Building at Kenn...

22/10/2025

Hybrid SATCOM: Delivering Resilient and Agile Connectivity Today

L3Harris' Hybrid SATCOM is resilient by design, offering path diversity that eliminates vulnerabilities by routing data across the best available networks i...

22/10/2025

The 2025 NAB Show New York Opens With More Than 12,000 Attendees Expected

WASHINGTON, D.C. Organizers of NAB Show New York said they are expecting more than 12,000 registered attendees from about 100 countries along with 260 exhibitor...

22/10/2025

The 2025 NAB Show New York Set to Open with More Than 12,000 Attendees Expected

WASHINGTON, D.C The organizers of The 2025 NAB Show New York have announced that they are expecting more than 12,000 registered attendees from about 100 countr...

22/10/2025

Masque Sound and Jaffe Holden Create Transformative Perfo...

Masque Sound, a leading theatrical sound reinforcement, installation and design company, supplied an extensive gear package of professional-grade equipment for ...

22/10/2025

Lightware UCX-3x3-TPX-RX20 sets new standard for connecte...

Lightware, a global leader in signal management and AV connectivity solutions, is seeing strong market momentum for the UCX-3x3-TPX-RX20, a compact transmitter-...

22/10/2025

Chyron Releases PAINT 10.2 Telestration Platform

MELVILLE, N.Y. Chyron has released PAINT 10.2, the latest update for its telestration platform, adding support for SMPTE ST 2110 IP workflows, expanding brandin...

22/10/2025

NBCUniversal Invests in ATSC 3.0 Authority Behind Run3TV

WASHINGTON Run3TV today said NBCUniversal is joining as an investor in the ATSC 3.0 Framework Authority, which develops the Run3TV NextGen TV application platfo...

22/10/2025

swXtch.io to Feature SRT-X Gateway, groundSwXtch at NAB Show New York

ATLANTA swXtch.io will feature two new networking solutions extending the company's reach across more cloud and on-prem workflows at NAB Show New York, set ...

22/10/2025

HBO Max Increases Prices for All Tiers

The Warner Bros. Discoverys HBO Max streaming services has increased prices for all its streaming tiers effectively immediately for new customers. Existing cust...