Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Proposed: a Bounty for Bugs
Mark Rasch, 2003-11-10

Instead of paying hard cash to punish computer criminals, vendors should reward grey hat hackers for responsibly finding and reporting the security holes that make cyber attacks possible.

Comments Mode:
Proposed: a Bounty for Bugs 2003-11-10
researcher
Proposed: a Bounty for Bugs 2003-11-11
Anonymous (1 replies)
Proposed: a Bounty for Bugs 2003-11-13
Mark Rasch
Proposed: a Bounty for Bugs 2003-11-11
Psuedo-Anonymous Coward (1 replies)
Proposed: a Bounty for Bugs 2003-11-19
Anonymous
Proposed: a Bounty for Bugs 2003-11-11
Anonymous (1 replies)
Proposed: a Bounty for Bugs 2003-11-13
Anonymous
Proposed: a Bounty for Bugs 2003-11-11
agent1
Proposed: a Bounty for Bugs 2003-11-11
Ragnarok
Proposed: a Bounty for Bugs 2003-11-11
Theuns
Proposed: a Bounty for Bugs 2003-11-11
frustrated security dweeb
Proposed: a Bounty for Bugs 2003-11-12
Bob Weiss - Passsword Crackers, Inc.
I added a comment to the OIS proposal regarding requests for compensation from security researchers who have identified vulnerabilities. The gist of the comment was that I felt that the OIS proposal did not deal with when and how such a request would be legitimate. I think that creating an economic incentive for finding and exposing vulnerabilities or bugs is a good way to go. This issue is not only about notification, but should also be about incentive. Serious security researchers cannot be expected to continue to expose flaws out of the goodness of their hearts. They become, in effect, QC and testers for the manufacturers. Quality research in this area should be compensated. Initially, I thought that the guidelines might embrace a methodology for negotaition between the manufacturer and researcher, but a fixed "bounty" might also be a way to go. I expect that the "bounty" should not be high enough to be punitive, but should be based on some reasonable estimate of the amount of time that can go into this work. Punitive penalties will be handed out by the courts, eventually, when enough users are hurt by a software company that knowingly releases software that is insecure. A "bug bounty" would open the market to a wide range of hackers and security professionals who would actively identify flaws and vulnerabilities. Combined with an industry standard for proper notification of users and some time for manufacturers to issue and test patches I think we would be approaching a better paradigm for the identification and remediation of security bugs by a broad community that is properly incentivized.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/197/23637#23637
Proposed: a Bounty for Bugs 2003-11-12
Lockdown
Proposed: a Bounty for Bugs 2003-11-12
Anonymous
Proposed: a Bounty for Bugs: A Notoriously Bad Idea 2003-11-12
Michael Sierchio (1 replies)
Proposed: a Bounty for Bugs 2003-11-13
Anonymous
Proposed: a Bounty for Bugs 2003-11-13
Anonymous
Proposed: a Bounty for Bugs 2003-11-13
Sunil James - Director, iDEFENSE
Proposed: a Bounty for Bugs 2003-11-14
Administrator
Proposed: a Bounty for Bugs 2003-11-14
Anonymous
Proposed: a Bounty for Bugs 2003-11-15
Anonymous (1 replies)
Proposed: a Bounty for Bugs 2003-11-18
intruder
Proposed: a Bounty for Bugs 2003-11-18
Anonymous
Old idea ... 2003-11-19
Garry







 

Privacy Statement
Copyright 2008, SecurityFocus