EconPapers    
Economics at your fingertips  
 

The Simple Economics of an External Shock on a Crowdsourced "Bug Bounty Platform"

Aviram Zrahia, Neil Gandal, Sarit Markovich and Michael Riordan

No 17443, CEPR Discussion Papers from Centre for Economic Policy Research

Abstract: In this paper, we first provide background on the "nuts and bolts" of a bug bounty platform a two-sided marketplace that connects firms and individual security researchers ("ethical" hackers) to find and be rewarded for discovering software vulnerabilities. We then empirically examine the effect of an exogenous external shock (Covid-19) on Bugcrowd, one of the two largest "two-sided" bug bounty platforms. The shock reduced the opportunity set for many security researchers who either lost their jobs or were placed on a leave of absence. We show that the exogenous shock led to a huge rightward (downward) shift in the supply curve and to an increase both in the number of submissions and new researchers on the platform. The results suggest that had there been a larger increase in number of firms with bug bounty programs on the platform, many more unique software vulnerabilities would have been discovered. We quantify the benefits to the platform from the exogenous shock which enables us to shed light on the benefits associated with the gig economy.

Keywords: Bug bounty programs; Platform; Covid-19 (search for similar items in EconPapers)
Date: 2022-07
References: Add references at CitEc
Citations:

Downloads: (external link)
https://cepr.org/publications/DP17443 (application/pdf)

Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.

Export reference: BibTeX RIS (EndNote, ProCite, RefMan) HTML/Text

Persistent link: https://EconPapers.repec.org/RePEc:cpr:ceprdp:17443

Ordering information: This working paper can be ordered from
https://cepr.org/publications/DP17443

Access Statistics for this paper

More papers in CEPR Discussion Papers from Centre for Economic Policy Research 33 Great Sutton Street, London EC1V 0DX, UK.
Bibliographic data for series maintained by CEPR ().

 
Page updated 2026-05-29
Handle: RePEc:cpr:ceprdp:17443