{"id":105165,"date":"2022-03-24T09:45:09","date_gmt":"2022-03-24T16:45:09","guid":{"rendered":"https:\/\/www.backblaze.com\/blog\/?p=105165"},"modified":"2022-07-13T23:37:45","modified_gmt":"2022-07-14T06:37:45","slug":"calling-all-security-researchers-join-the-backblaze-bug-bounty-program","status":"publish","type":"post","link":"https:\/\/www.backblaze.com\/blog\/calling-all-security-researchers-join-the-backblaze-bug-bounty-program\/","title":{"rendered":"Calling All Security Researchers: Join the Backblaze Bug Bounty Program"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-105168\" src=\"https:\/\/www.backblaze.com\/blog\/wp-content\/uploads\/2022\/03\/Bug-Bounty-Program-Announcement-1.png\" alt=\"\" width=\"1440\" height=\"820\" srcset=\"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2022\/03\/Bug-Bounty-Program-Announcement-1.png 1440w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2022\/03\/Bug-Bounty-Program-Announcement-1-300x171.png 300w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2022\/03\/Bug-Bounty-Program-Announcement-1-1024x583.png 1024w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2022\/03\/Bug-Bounty-Program-Announcement-1-768x437.png 768w, https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2022\/03\/Bug-Bounty-Program-Announcement-1-560x319.png 560w\" sizes=\"auto, (max-width: 1440px) 100vw, 1440px\" \/><\/p>\n<p id=\"bzdropcap\">Here at Backblaze, we help people build applications, host content, manage media, back up and archive data, and more securely in the cloud\u2014and that \u201csecurely\u201d part of the equation has always been paramount. We use a variety of tools and techniques to stay ahead of any potential security threats, including our participation over the past year plus in the Bugcrowd security platform. Today, we are opening up our <a href=\"https:\/\/bugcrowd.com\/backblaze\" target=\"_blank\" rel=\"noopener\">Bugcrowd Bug Bounty Program<\/a> to all security researchers.<\/p>\n<p>Now, anyone can join Bugcrowd and start hacking away at our desktop and mobile apps, APIs, or web applications in order to help us find any vulnerabilities and strengthen the security of our services. Read on to learn more about the program and the other measures we take to spot and address potential security vulnerabilities.<\/p>\n<div class=\"abstract\" style=\"line-height: 1.8; margin: 24px 12px; padding: 24px 12px 10px 12px;\">Join Ola Nordstrom, Lead Application Security Engineer; Chris Vickery, Senior Risk Assessment Specialist; and Pat Patterson, Chief Developer Evangelist, on April 21, 2022 at 1 p.m. PDT to learn more about why we decided to implement the Bugcrowd Bug Bounty Program, how it fits into the Backblaze security portfolio, and how you can join in on either side: as hacker or hackee.<\/p>\n<p><!--HubSpot Call-to-Action Code --><span id=\"hs-cta-wrapper-fc6aac79-755c-459c-9b35-e9a702c9d6bb\" class=\"hs-cta-wrapper\"><span id=\"hs-cta-fc6aac79-755c-459c-9b35-e9a702c9d6bb\" class=\"hs-cta-node hs-cta-fc6aac79-755c-459c-9b35-e9a702c9d6bb\"><!-- [if lte IE 8]>\n\n\n<div id=\"hs-cta-ie-element\"><\/div>\n\n\n<![endif]--><a href=\"https:\/\/cta-redirect.hubspot.com\/cta\/redirect\/2832298\/fc6aac79-755c-459c-9b35-e9a702c9d6bb\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" id=\"hs-cta-img-fc6aac79-755c-459c-9b35-e9a702c9d6bb\" class=\"hs-cta-img\" style=\"border-width: 0px;\" src=\"https:\/\/no-cache.hubspot.com\/cta\/default\/2832298\/fc6aac79-755c-459c-9b35-e9a702c9d6bb.png\" alt=\"\u2794 Register for the Webinar Today\" \/><\/a><\/span><script charset=\"utf-8\" src=\"https:\/\/js.hscta.net\/cta\/current.js\"><\/script><script type=\"text\/javascript\"> hbspt.cta.load(2832298, 'fc6aac79-755c-459c-9b35-e9a702c9d6bb', {\"useNewLoader\":\"true\",\"region\":\"na1\"}); <\/script><\/span><!-- end HubSpot Call-to-Action Code --><\/div>\n<h2><strong>How Backblaze Keeps Customer Data Safe<\/strong><\/h2>\n<p>Over the years, Backblaze has consistently invested in maintaining and upgrading its security portfolio. User files are <a href=\"https:\/\/www.backblaze.com\/cloud-storage\/security\" target=\"_blank\" rel=\"noopener\">encrypted by default<\/a>, we also support <a href=\"\/blog\/server-side-encryption-keys-to-more-protection\/\" target=\"_blank\" rel=\"noopener\">server-side encryption for the Backblaze S3 Compatible API<\/a>, and have doubled the size of our Security team over the last year under the leadership of CISO <a href=\"https:\/\/www.linkedin.com\/in\/markepotter\/\" target=\"_blank\" rel=\"noopener\">Mark Potter<\/a>.<\/p>\n<p>But all those security features and frankly all software, not just Backblaze, are vulnerable to security bugs that can expose user information and data. Oftentimes, these are caused by implementation mistakes or changes in how a piece of software is used over time. The recent <a href=\"https:\/\/www.bugcrowd.com\/resources\/log4shell\/\" target=\"_blank\" rel=\"noopener\">Log4j (aka Log4Shell) vulnerability<\/a> affected nearly everyone due to its ubiquitous use across software platforms and the industry as a whole.<\/p>\n<p>I&#8217;ve been working to secure software my whole career. Before the advent of crowdsourced security platforms such as Bugcrowd, managing vulnerability reports was a painful task. Emails, typically sent to security@company.tld, were copied back and forth between bug tracking platforms. Reviewing submissions and gathering metrics was difficult since every engineering team or organization always had their own process for tagging and categorizing bug reports. Everything was copied back and forth to make any sense of the data (Think Excel spreadsheets!). In a world where zero-day vulnerabilities are commonplace, such processes are just too slow and you end up playing catch-up with the bad guys.<\/p>\n<h3><strong>How Does Bugcrowd Fit Into the Backblaze Security Portfolio?<\/strong><\/h3>\n<p>Bugcrowd takes the grunt work out of the process to let us focus on addressing the vulnerability and communicating with researchers. Bugcrowd encourages white hat hackers to attack businesses, find vulnerabilities in their software and processes, and aid in guiding the remediation of those vulnerabilities before they can be exploited by anyone else.<\/p>\n<p>What\u2019s more, and perhaps most important to security researchers around the world, is that Bugcrowd allows us to pay security researchers for finding vulnerabilities. Without Bugcrowd, Backblaze wouldn&#8217;t have a cost-effective way to pay for a bug report from a researcher in another country or another continent. It\u2019s only fair we pay for the work they do to help us out, and in addition, having a public program ensures transparency and fairness for everyone.<\/p>\n<h2><strong>How You Can Join the Backblaze Bugcrowd Bug Bounty Program<\/strong><\/h2>\n<p>Backblaze\u2019s private beta has been running for over a year, but now that the program is public, any interested security researcher can sign up to hack away the company\u2019s in-scope products and networks. If you think you\u2019ve found a vulnerability or you\u2019d like more information about the in-scope products, URLs, or bounty ranges, check out the Backblaze Bugcrowd Bug Bounty Program <a href=\"https:\/\/www.bugcrowd.com\/backblaze\" target=\"_blank\" rel=\"noopener\">here<\/a>. And, don\u2019t forget to <a href=\"https:\/\/www.brighttalk.com\/webcast\/14807\/535410?utm_source=Bzwebsite&amp;utm_medium=Blog&amp;utm_campaign=webinar_general\" target=\"_blank\" rel=\"noopener\">register for our webinar<\/a> to learn more about the program.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Backblaze Bugcrowd Bug Bounty Program is now open to all security researchers! Learn more about the program and the other measures we take to address potential security vulnerabilities.<\/p>\n","protected":false},"author":176,"featured_media":105168,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"content-type":"","footnotes":""},"categories":[121],"tags":[469],"class_list":["post-105165","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-backing-up","tag-consumerbackup","entry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Calling All Security Researchers: Join the Backblaze Bug Bounty Program<\/title>\n<meta name=\"description\" content=\"The Backblaze Bug Bounty program helps us squash bugs before they impact your hard drive. Learn more about Bugcrowd and how you can join the program today.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.backblaze.com\/blog\/calling-all-security-researchers-join-the-backblaze-bug-bounty-program\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Calling All Security Researchers: Join the Backblaze Bug Bounty Program\" \/>\n<meta property=\"og:description\" content=\"The Backblaze Bug Bounty program helps us squash bugs before they impact your hard drive. Learn more about Bugcrowd and how you can join the program today.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/backblazeprod.wpenginepowered.com\/blog\/calling-all-security-researchers-join-the-backblaze-bug-bounty-program\/\" \/>\n<meta property=\"og:site_name\" content=\"Backblaze Blog | Cloud Storage &amp; Cloud Backup\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/backblaze\" \/>\n<meta property=\"article:published_time\" content=\"2022-03-24T16:45:09+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-07-14T06:37:45+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2022\/03\/Bug-Bounty-Program-Announcement-1.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1440\" \/>\n\t<meta property=\"og:image:height\" content=\"820\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Ola Nordstrom\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@backblaze\" \/>\n<meta name=\"twitter:site\" content=\"@backblaze\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ola Nordstrom\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Calling All Security Researchers: Join the Backblaze Bug Bounty Program","description":"The Backblaze Bug Bounty program helps us squash bugs before they impact your hard drive. Learn more about Bugcrowd and how you can join the program today.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.backblaze.com\/blog\/calling-all-security-researchers-join-the-backblaze-bug-bounty-program\/","og_locale":"en_US","og_type":"article","og_title":"Calling All Security Researchers: Join the Backblaze Bug Bounty Program","og_description":"The Backblaze Bug Bounty program helps us squash bugs before they impact your hard drive. Learn more about Bugcrowd and how you can join the program today.","og_url":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/calling-all-security-researchers-join-the-backblaze-bug-bounty-program\/","og_site_name":"Backblaze Blog | Cloud Storage &amp; Cloud Backup","article_publisher":"https:\/\/www.facebook.com\/backblaze","article_published_time":"2022-03-24T16:45:09+00:00","article_modified_time":"2022-07-14T06:37:45+00:00","og_image":[{"width":1440,"height":820,"url":"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2022\/03\/Bug-Bounty-Program-Announcement-1.png","type":"image\/png"}],"author":"Ola Nordstrom","twitter_card":"summary_large_image","twitter_creator":"@backblaze","twitter_site":"@backblaze","twitter_misc":{"Written by":"Ola Nordstrom","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/calling-all-security-researchers-join-the-backblaze-bug-bounty-program\/#article","isPartOf":{"@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/calling-all-security-researchers-join-the-backblaze-bug-bounty-program\/"},"author":{"name":"Ola Nordstrom","@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/#\/schema\/person\/069c7a9a5320c7773971e0261ef86dba"},"headline":"Calling All Security Researchers: Join the Backblaze Bug Bounty Program","datePublished":"2022-03-24T16:45:09+00:00","dateModified":"2022-07-14T06:37:45+00:00","mainEntityOfPage":{"@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/calling-all-security-researchers-join-the-backblaze-bug-bounty-program\/"},"wordCount":664,"commentCount":0,"publisher":{"@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/#organization"},"image":{"@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/calling-all-security-researchers-join-the-backblaze-bug-bounty-program\/#primaryimage"},"thumbnailUrl":"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2022\/03\/Bug-Bounty-Program-Announcement-1.png","keywords":["ConsumerBackup"],"articleSection":["Backing Up"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/backblazeprod.wpenginepowered.com\/blog\/calling-all-security-researchers-join-the-backblaze-bug-bounty-program\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/calling-all-security-researchers-join-the-backblaze-bug-bounty-program\/","url":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/calling-all-security-researchers-join-the-backblaze-bug-bounty-program\/","name":"Calling All Security Researchers: Join the Backblaze Bug Bounty Program","isPartOf":{"@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/calling-all-security-researchers-join-the-backblaze-bug-bounty-program\/#primaryimage"},"image":{"@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/calling-all-security-researchers-join-the-backblaze-bug-bounty-program\/#primaryimage"},"thumbnailUrl":"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2022\/03\/Bug-Bounty-Program-Announcement-1.png","datePublished":"2022-03-24T16:45:09+00:00","dateModified":"2022-07-14T06:37:45+00:00","description":"The Backblaze Bug Bounty program helps us squash bugs before they impact your hard drive. Learn more about Bugcrowd and how you can join the program today.","breadcrumb":{"@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/calling-all-security-researchers-join-the-backblaze-bug-bounty-program\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/backblazeprod.wpenginepowered.com\/blog\/calling-all-security-researchers-join-the-backblaze-bug-bounty-program\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/calling-all-security-researchers-join-the-backblaze-bug-bounty-program\/#primaryimage","url":"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2022\/03\/Bug-Bounty-Program-Announcement-1.png","contentUrl":"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2022\/03\/Bug-Bounty-Program-Announcement-1.png","width":1440,"height":820},{"@type":"BreadcrumbList","@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/calling-all-security-researchers-join-the-backblaze-bug-bounty-program\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Calling All Security Researchers: Join the Backblaze Bug Bounty Program"}]},{"@type":"WebSite","@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/#website","url":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/","name":"Backblaze Cloud Solutions Blog","description":"Cloud Storage &amp; Cloud Backup","publisher":{"@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/#organization","name":"Backblaze","url":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/i0.wp.com\/www.backblaze.com\/blog\/wp-content\/uploads\/2017\/12\/backblaze_icon_transparent.png?fit=512%2C512&ssl=1","contentUrl":"https:\/\/i0.wp.com\/www.backblaze.com\/blog\/wp-content\/uploads\/2017\/12\/backblaze_icon_transparent.png?fit=512%2C512&ssl=1","width":512,"height":512,"caption":"Backblaze"},"image":{"@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/backblaze","https:\/\/x.com\/backblaze","https:\/\/www.youtube.com\/user\/Backblaze","https:\/\/en.wikipedia.org\/wiki\/Backblaze"]},{"@type":"Person","@id":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/#\/schema\/person\/069c7a9a5320c7773971e0261ef86dba","name":"Ola Nordstrom","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2022\/03\/ola-profile-for-blog-150x150.jpg","url":"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2022\/03\/ola-profile-for-blog-150x150.jpg","contentUrl":"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2022\/03\/ola-profile-for-blog-150x150.jpg","caption":"Ola Nordstrom"},"description":"Ola is the lead application security engineer at Backblaze. With two decades of experience developing and securing software on a range of platforms, Ola works diligently to keep your backups safe. Whether it's written in assembly, Javascript, or any language in between, he strives to find and fix both implementation vulnerabilities and architectural weaknesses before they make their way into production. Ola has an M.S. in computer science, is published, and has several patents covering software, authentication, and security. Connect with him on LinkedIn.","url":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/author\/ola\/"}]}},"jetpack_featured_media_url":"https:\/\/backblazeprod.wpenginepowered.com\/wp-content\/uploads\/2022\/03\/Bug-Bounty-Program-Announcement-1.png","_links":{"self":[{"href":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/wp-json\/wp\/v2\/posts\/105165","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/wp-json\/wp\/v2\/users\/176"}],"replies":[{"embeddable":true,"href":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/wp-json\/wp\/v2\/comments?post=105165"}],"version-history":[{"count":0,"href":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/wp-json\/wp\/v2\/posts\/105165\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/wp-json\/wp\/v2\/media\/105168"}],"wp:attachment":[{"href":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/wp-json\/wp\/v2\/media?parent=105165"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/wp-json\/wp\/v2\/categories?post=105165"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/backblazeprod.wpenginepowered.com\/blog\/wp-json\/wp\/v2\/tags?post=105165"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}