A bug bounty program is a deal offered by many websites, organizations and software developers by which individuals can receive recognition and compensation [1] for reporting bugs, especially those pertaining to exploits and vulnerabilities. These programs allow the developers to discover and resolve bugs before the general public is aware of them, preventing incidents of widespread abuse. Bug bounty programs have been implemented by a large number of organizations, including Mozilla,[2][3] Facebook,[4] Yahoo!,[5] Google,[6] Reddit,[7] Square,[8] and Microsoft.[9][10] Companies outside the technology industry, including traditionally conservative organizations like the United States Department of Defense, have started using bug bounty programs. [11] The Pentagon’s use of bug bounty programs is part of a posture shift that has seen several US Government Agencies reverse course from threatening white hat hackers with legal recourse to inviting them to participate as part of a comprehensive vulnerability disclosure framework or policy. [12]