How Riot Runs Its Bug Bounty Program For League Of Legends

“Bug bounty” programs are becoming more popular with developers, especially larger firms that can afford the expenditure. A couple of game studios have also employed the approach, with Riot of League of Legends fame starting one up a few years ago. But how are such programs managed internally?

Riot information security engineer David Rook has both a video presentation and blog post explaining how the game developer handles its program.

Surprisingly, it’s the written post that has the condensed coverage, so if you just want an overview, that’s where you should go:

1. Fight together, not with each other
2. Make researchers feel like part of the team
3. KISS (Keep It Simple, Stupid) when it comes to program scope
4. Value researchers’ time and reward them well
5. Build a world class program to attract the best researchers

The video provides a more in-depth look at Riot’s processes, though the focus is on the day-to-day running of the program. Even if you’re only a smidge curious, it’s definitely worth a watch.

RUNNING A BUG BOUNTY PROGRAM [Riot Games]


The Cheapest NBN 50 Plans

Here are the cheapest plans available for Australia’s most popular NBN speed tier.

At Lifehacker, we independently select and write about stuff we love and think you'll like too. We have affiliate and advertising partnerships, which means we may collect a share of sales or other compensation from the links on this page. BTW – prices are accurate and items in stock at the time of posting.

Comments


Leave a Reply