United In Its Bug Bounty Program Offers Air Miles as Reward to Researchers

United Airlines has launched a bug bounty program which offers air miles as a reward for researchers who discover flaws in its web portals.

The Bug bounty programs are increasingly gaining popularity as incidents of cybercrime are increasing.

Companies such as Google and Facebook use these programs to let the third-parties and users to keep an eye on their systems and also former reward for disclosure to lure hackers away from selling the information on the black market.

United Airlines, however, has chosen to offer air miles, for the task, depending on the severity of the bug discovered instead of cash.

The airlines said in statement, “If you think you have discovered a potential bug that affects our websites, apps and/or online portals, please let us know. If the submission meets our requirements, we'll gladly reward you for your time and effort”.

Air miles are basically available for those who discover a bug in customer-facing websites and third-party programs which affects the confidentiality, integrity and/or availability of customer or company information.

Cross-site scripting, cross-site request forgery and third-party issues affecting United are classified as low-severity and are worth 50,000 air miles.

Researchers can access 250,000 air miles per vulnerability classified as medium-severity, such as authentication bypass, brute force attacks and issues that could lead to personal data being disclosed.

And by discovering high-security vulnerability such as remote code execution researchers will be able to earn a maximum of 1 million air miles.

Unites said, those interested in participating in the bug bounty program will need to be MileagePlus members.

The airline is only looking to unearth bugs in customer-facing systems, and issues with legacy systems, operating systems, onboard wi-fi, internal websites or entertainment systems are not eligible.