Skip to main content

Programmer hits the jackpot with United bug bounty program

Jordan Weins has become the first researcher to claim a huge miles bounty form United Airlines in return for reporting a remote-code execution error in their site.

Back in May United Airlines began offering mile rewards for reporting bugs in their online systems. The move was largely a response to criticism the airline faced after it booted a programs researcher off one of its flights. The boot was a punishment they saw fit when the researcher tweet about an exploit he found in the flights onboard systems. The mile rewards is offered in tiers depending on the severity of the issue found and of course reported.

Recommended Videos

United said it will reward the finding of “basic third-party issues affecting its systems with 50,000 miles, exploits that could jeopardize the confidentiality of customer information get 250,000 miles, and major flaws related to remote-code execution earn a maximum of 1,000,000 miles.” Other companies have also been known to offer bounties in an attempt to dissuade savvy programmers from taking advantage of flaws and instead turn them in for cash. The list includes heavy-weight tech names like Google, Facebook, and Yahoo!.

Related: Major bug grounded United flights, halted trading on NYSE

It was the first time that Weins had ever submitted to a bug bounty program, and he had no intention of receiving the grand prize. “There were actually two bugs that I submitted that I were pretty sure were remote code execution, but I also thought they were lame and wasn’t sure if they were on parts of the infrastructure that qualified,” Wiens told the ThreatPost security blog. “My expectation was that they counted, but I figured they’d award me 50,000 miles or something smaller.” One can imagine his surprise when United Airlines contacted Weins and told him to check his account, wherein he found many a vacation waiting for him.

While the gesture is certainly good for United publicity, it may also serve as bait for future researchers to submit, hoping to get the grand prize. Best of luck to all the hackers out there.

Andre Revilla
Andre Revilla is an entrepreneur and writer based in Chicago that has been covering and working in the consumer tech space…
AMD’s RDNA 4 may surprise us in more ways than one
AMD RX 7800 XT and RX 7700 XT graphics cards.

Thanks to all the leaks, I thought I knew what to expect with AMD's upcoming RDNA 4. It turns out I may have been wrong on more than one account.

The latest leaks reveal that AMD's upcoming best graphics card may not be called the RX 8800 XT, as most leakers predicted, but will instead be referred to as the  RX 9070 XT. In addition, the first leaked benchmark of the GPU gives us a glimpse into the kind of performance we can expect, which could turn out to be a bit of a letdown.

Read more
This futuristic mechanical keyboard will set you back an eye-watering $1,600
Hands typing on The Icebreaker keyboard.

I've complained plenty about how some of the best gaming keyboards are too expensive, from the Razer Black Widow V4 75% to the Wooting 80HE, but nothing comes remotely close to The Icebreaker. Announced nearly a year ago by Serene Industries, The Icebreaker is unlike any keyboard I've ever seen -- and it's priced accordingly at $1,600. Plus shipping, of course.

What could justify such an extravagant price? Aluminum, it turns out. The keyboard is constructed of one single block of 6061 aluminum in what Serene Industries calls an "unorthodox wedge form." As if that wasn't enough metal, the keycaps are also made of aluminum, and Serene says they include "about 800" micro-perforations that allow the LED backlight of the keyboard to shine through.

Read more
Google one-ups Microsoft by making chats easier to transfer
Google Spaces in Google Chat on a MacBook.

In a recent blog post, Google announced that it is making it easier for admins to migrate from Microsoft Teams to Google Chat to reduce downtime. Admins can easily do this within the Google Chat migration menu and connect to opposing Microsoft accounts to transfer Teams data.

Google gave step-by-step instructions for admins on how to transfer the messages. Admins need to connect to their Microsoft account and upload a CSV of the Teams from where they transfer the messages. From there, it requires just entering a starting date for messages to be migrated from Teams and clicking Star migration. Once it's complete, it'll make the migrated space, messages, and conversation data available to Google Workspace users.

Read more