Skip to main content

Bug Bounties: Ethical and Legal Aspects

  • Chapter
  • First Online:
Legal Developments on Cybersecurity and Related Fields

Part of the book series: Law, Governance and Technology Series ((LGTS,volume 60))

Abstract

Bug bounty programs are a new approach to pen-testing. Through them, organisations are willing to test their products taking advantage of hackers spread all over the world. So, the number of vulnerabilities found increases and the cost of detecting them becomes lower. To maintain some control over what hackers can do, organisations specify a set of rules. Through these rules, organisations try to limit the actions to be performed and to give confidence to ethical hackers conduct activities that are typically illegal without being worried with the risk of legal violations. This article presents an analysis of the current state of bug bounty programs. The analysis focuses on economic, ethical, and legal aspects and highlights several problems related to these aspects. Given the current state of these programs, it is important that national bodies responsible for cybersecurity, address the challenges imposed by these programs. National and international rules are needed to both ethically and legally protect the parties and contribute to regulate an activity that many still consider illegal. Without that, a set of alternative solutions to “legalize” them in an ad-hoc and unclear way will continue to proliferate creating ethical and legal problems.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Subscribe and save

Springer+ Basic
$34.99 /Month
  • Get 10 units per month
  • Download Article/Chapter or eBook
  • 1 Unit = 1 Article or 1 Chapter
  • Cancel anytime
Subscribe now

Buy Now

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD 139.00
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Hardcover Book
USD 179.99
Price excludes VAT (USA)
  • Durable hardcover edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Similar content being viewed by others

References

Download references

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to João Paulo Magalhães .

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2024 The Author(s), under exclusive license to Springer Nature Switzerland AG

About this chapter

Check for updates. Verify currency and authenticity via CrossMark

Cite this chapter

Magalhães, J.P. (2024). Bug Bounties: Ethical and Legal Aspects. In: Carneiro Pacheco de Andrade, F.A., Fernandes Freitas, P.M., de Sousa Covelo de Abreu, J.R. (eds) Legal Developments on Cybersecurity and Related Fields. Law, Governance and Technology Series, vol 60. Springer, Cham. https://doi.org/10.1007/978-3-031-41820-4_14

Download citation

  • DOI: https://doi.org/10.1007/978-3-031-41820-4_14

  • Published:

  • Publisher Name: Springer, Cham

  • Print ISBN: 978-3-031-41819-8

  • Online ISBN: 978-3-031-41820-4

  • eBook Packages: Law and CriminologyLaw and Criminology (R0)

Publish with us

Policies and ethics