Tired of ads? Enjoy an ad-free experience by signing up.
Jack Ellis · · 2 min read

Grab offers hackers bug bounty

Grab cars in Singapore.

Grab is offering rewards of up to US$10,000 to hackers who are able to identify security weaknesses in its ride-hailing platform.

The Singapore-based ride-hailer this week called for the public to participate in the “bug bounty” program it runs in partnership with HackerOne, a startup that handles cybersecurity testing tasks both privately and through crowdsourcing. Grab has previously worked with HackerOne in closed, rather than public, security tests
. This existing program has enabled the resolution of nearly 200 vulnerability issues in Grab’s platform so far.

Organizations including Adobe, Intel, Qualcomm, and the US Department of Defense have used HackerOne’s solution.

Under the new program, Grab will give hackers prizes of between US$100 and US$10,000 depending on the severity of the security issues that they discover.

If hackers are able to find what Grab calls “critical security issues” – including exposure of personal data such as customer numbers, driver images, license numbers, location information, and payment card information – they will be eligible to receive rewards in the range of US$5,000 and US$10,000.

Uber – one of Grab’s key competitors – also runs a bug bounty program via HackerOne. It similarly offers rewards of up to US$10,000 for the discovery of critical security issues. India’s Ola reportedly offers hackers rewards starting at around US$17 for uncovering flaws in its platform.

Indonesia’s Go-Jek – another of Grab’s major ride-hailing rivals in the region – has had the security of its platform questioned on numerous occasions. Last year, a hacker claimed to have revealed security flaws in Go-Jek’s app, while several users reported that Go-Pay – the company’s payments service – had been compromised. In response to the latter Go-Jek suggested that user accounts, rather than its system, had been hacked because users had not selected effective passwords. Go-Jek recently launched its own bug bounty program.

Editing by Nadine Freischlad and Steven Millward

(And yes, we’re serious about ethics and transparency. More information here.)

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.

Community Writer

Jack Ellis

Sweltering in Singapore. Got a news tip? Email me at jack@techinasia.com