Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Lazada Opened Its Public Bug Bounty Program in 2021: What Researchers Should Know

Lazada’s public bug bounty launched in 2021 after an 18-month private phase. Its security page now points vulnerability reporters to Alibaba’s security site, but current reward terms should be checked in the live rules.
From TheFinanceBase Team2 min to read

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Lazada announced its public bug bounty program with YesWeHack on June 10, 2021, following a private program that began in January 2020. The launch announcement said critical reports could earn up to US$10,000, but that was a 2021 figure—not a verified current reward. Today, Lazada’s security page directs vulnerability reports to Alibaba’s security site; anyone considering testing should first check the live program rules.

When did Lazada launch its public bug bounty?

Lazada Group announced the public program on June 10, 2021, in partnership with YesWeHack. It opened the program to the wider cybersecurity community after an 18-month private phase that began in January 2020. Lazada said the private program was intended to help identify vulnerabilities in its IT environment.

In its 2021 announcement, Lazada reported that more than 100 ethical hackers had participated in the private program and that it had awarded more than US$150,000 before or at the public launch. Those are company-reported historical totals, not independent assessments or current program statistics. Read Lazada’s June 10, 2021 announcement.

What rewards did the 2021 announcement describe?

The announcement said critical reports could receive up to US$10,000. Lazada highlighted high- and critical-severity vulnerabilities affecting personal data. The amount is the maximum stated at launch in 2021; the reviewed current security page does not establish a present-day reward ceiling or payment terms.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Bug bounty programs generally offer rewards for qualifying vulnerabilities in defined assets under program rules. A vulnerability disclosure policy, by contrast, can provide a channel for reporting issues without an expectation of financial reward. This is YesWeHack’s general distinction, not a substitute for the terms of any particular Lazada program. YesWeHack explains the difference between bug bounties and vulnerability disclosure policies.

Where does Lazada direct vulnerability reports now?

Lazada’s security page directs people reporting vulnerabilities to the Lazada Bug Bounty Program at Alibaba’s security site. Its “Cakupan Bug Bounty” section lists country-domain scope information for Singapore, Vietnam, Indonesia, the Philippines, Malaysia, and Thailand. That country-specific list is not necessarily a complete asset inventory, and a listed domain should not be treated by itself as permission to test it. See Lazada’s security page.

Alibaba Security Response Center (ASRC) describes itself as Alibaba’s security contact. It says it operates a threat bounty program, coordinates with researchers and partners, and helps developers address vulnerabilities. That general description does not establish the detailed current terms for Lazada’s program. Visit Alibaba Security Response Center.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should researchers verify before testing?

Before conducting any security testing, consult the live Lazada program rules through the reporting link on Lazada’s security page. The reviewed pages do not establish a complete current scope, eligibility requirements, safe-harbor terms, testing restrictions, or current reward amounts. Do not infer authorization from the 2021 announcement or from the country-domain list alone.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Lazada’s launch announcement quoted then-Chief Risk Officer Alan Chan as saying the company had worked to patch vulnerabilities to protect customers and personal information. Then-Head of Cyberdefence Franck Vervial described the launch as a signal that Lazada valued the data in its possession. Those statements explain the launch-era rationale; they do not describe current program conditions.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.