This module presented six noteworthy discoveries about HackerOne data and the economic model of bug bounties. I learned that we computed the elasticity of hacker supply for the first time in academic literature. Hackers are relatively price insensitive, with a median elasticity of 0.1 to 0.2. Second, I discovered that bug bounties are useful tools for businesses of all sizes and levels of renown. Third, I discovered that companies in particular industries received less reports than companies in other areas. Fourth, I discovered that the amount of new programs produced in any given month had a minor (and statistically negligible) impact on the number of reports received by companies on the HackerOne platform in that month. Fifth, I discovered that programs receive fewer reliable reports as time goes on. And lastly, through variable reports I learned that 60% of variation in valid reports remains unexplained and this puts an impact on the flow of vulnerabilities.
Finally, this module demonstrated how little we understand about bug bounty markets. We were unable to clearly identify the majority of the time-invariant variables that influenced hacker supply. Furthermore, our final fixed effects regression model explained less than half of the difference between data points. Future studies should concentrate on finding and quantifying more of the elements that influence hacker supply. Subsequent study will shed light on how bug bounty markets work, allowing us to better understand an increasingly vital cybersecurity tool.