AWS needs a bug bounty program

Andreas Wittig – 17 Sep 2020

A few weeks ago, while evaluating an AWS service, I stumbled upon an issue with the way the AWS API evaluates IAM policies for a particular IAM action. I contacted about that and was positively surprised about the professionalism in which the team handled my request. In the end, my reported issue was classified as a won’t fix. AWS updated the documentation to clarify the behavior. Fine!

AWS is missing a bug bounty program

The whole process made me think about how AWS handles vulnerability reports from its customers and ethical hackers. And I realized that AWS does not offer a bug bounty program. That’s a poor choice, in my opinion.


What is a bug bounty program? The deal is simple. An individual reports a bug to an organization and receives compensation in return. Most often, those bug bounty programs focus on security exploits and vulnerabilities. The bug bounty program sets the rules for reporting a bug and receiving compensation, typically based on severity. For example, when reporting a bug that could lead to remote code execution on Azure, Microsoft will pay you up to $40,000.1

Cover of Rapid Docker on AWS

Become a Docker on AWS professional!

Our book Rapid Docker on AWS is designed for DevOps engineers and web developers who want to run dockerized web applications on AWS. We lead you with many examples: From dockerizing your application to Continuous Deployment and Infrastructure as Code on AWS. No prior knowledge of Docker and AWS is required. Get the first chapter for free!


In my opinion, having a public bug bounty program is essential for two reasons:

  1. Filing a high-quality bug report is a lot of work. Customers who do the extra work of reporting their observations should be compensated. Otherwise, some bugs will never be reported.
  2. Attracting independent security experts - some call them ethical hackers - to uncover vulnerabilities provides an extra layer of protection.

I can’t find a reason for not having a bug bounty program.

Bug Bounty Program?

Let’s compare the major cloud providers

✅ Yes ❌ No
✅ Microsoft Azure1 ❌ Amazon Web Services
✅ Google Cloud Platform2 ❌ Oracle Cloud
✅ Alibaba Cloud3 ❌ IBM Cloud4
✅ Tencent Cloud5

Four of seven cloud providers offer a bug bounty program. Unfortunately, the market leader Amazon Web Services, does not. Even though AWS never misses an opportunity to assure security is their top priority. If these are not empty promises, I expect AWS to launch a bug bounty program soon!

  1. 1.
  2. 2.
  3. 3.
  4. 4. but does not offer any bounties
  5. 5.
Tags: aws security
Andreas Wittig

Andreas Wittig

I'm an independent consultant, technical writer, and programming founder. All these activities have to do with AWS. I'm writing this blog and all other projects together with my brother Michael.

In 2009, we joined the same company as software developers. Three years later, we were looking for a way to deploy our software—an online banking platform—in an agile way. We got excited about the possibilities in the cloud and the DevOps movement. It’s no wonder we ended up migrating the whole infrastructure of Tullius Walden Bank to AWS. This was a first in the finance industry, at least in Germany! Since 2015, we have accelerated the cloud journeys of startups, mid-sized companies, and enterprises. We have penned books like Amazon Web Services in Action and Rapid Docker on AWS, we regularly update our blog, and we are contributing to the Open Source community. Besides running a 2-headed consultancy, we are entrepreneurs building Software-as-a-Service products.

We are available for projects.

Feedback? Questions? Drop me a line: Email, Twitter, LinkedIn.

Briefcase icon
Hire me