Last week, Facebook published a report on its bug bounty program, which has been running since 2011. Hundreds of researchers have been rewarded under the program, and in 2013 alone, researchers' fees amounted to $1,500,000 (€1,080,000).
Over the past year, researchers have reported 14,763 vulnerabilities, a 246 percent increase over 2012. However, only 687 of them were eligible for a reward.
Furthermore, only 6% of the issues reported were of high severity and the average response time to address them was approximately 6 hours.
The average fee offered by Facebook to researchers was $2,204 (€1,600).
According to the company, the volume of high-severity vulnerabilities has decreased significantly this year, and experts emphasize that it is increasingly difficult to find critical vulnerabilities.
Most of the bugs discovered in 2013 affected websites and services of companies acquired by Facebook, not the social networking platform's core services.
Vulnerability reward programs are very important for businesses, as they show customers that they can use their services safely and without having to worry about their privacy being violated.

