Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Proposed: a Bounty for Bugs
Mark Rasch, 2003-11-10

Instead of paying hard cash to punish computer criminals, vendors should reward grey hat hackers for responsibly finding and reporting the security holes that make cyber attacks possible.

Comments Mode:
Proposed: a Bounty for Bugs 2003-11-10
researcher
Proposed: a Bounty for Bugs 2003-11-11
Anonymous (1 replies)
Proposed: a Bounty for Bugs 2003-11-13
Mark Rasch
Proposed: a Bounty for Bugs 2003-11-11
Psuedo-Anonymous Coward (1 replies)
Proposed: a Bounty for Bugs 2003-11-19
Anonymous
Proposed: a Bounty for Bugs 2003-11-11
Anonymous (1 replies)
Proposed: a Bounty for Bugs 2003-11-13
Anonymous
Proposed: a Bounty for Bugs 2003-11-11
agent1
Proposed: a Bounty for Bugs 2003-11-11
Ragnarok
Proposed: a Bounty for Bugs 2003-11-11
Theuns
Proposed: a Bounty for Bugs 2003-11-11
frustrated security dweeb
Proposed: a Bounty for Bugs 2003-11-12
Bob Weiss - Passsword Crackers, Inc.
Proposed: a Bounty for Bugs 2003-11-12
Lockdown
Proposed: a Bounty for Bugs 2003-11-12
Anonymous
Proposed: a Bounty for Bugs: A Notoriously Bad Idea 2003-11-12
Michael Sierchio (1 replies)
Proposed: a Bounty for Bugs 2003-11-13
Anonymous
There are some points that need considering here:

- Opensource

When the next BIND/OpenSSH/etc bug is found, who is going to pay up? In effect you'll be making it more worthwhile to rip into Windows than concentrate on the broad spectrum of software

- Penalties for Vendors

If the vendor does not issue an effective patch first time around (as MS have done in the past) or do not issue a patch in a timely manner they should pay a "fine" for remaining on the scheme. Perhaps this could fund payouts for OpenSource bugs?

- Severity

Who decides what is severe? According to MS the recent RPC flaws are not serious as long, according to Gates, as people have firewalls in place. Are we really saying that letting vendors rate their own vulns. that they are going to be honest?

Still, MS' bounty scheme demonstrates again that they just don't "get it" - thinking like this is good. Kudos for trying to think differently.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/197/23663#23663
Proposed: a Bounty for Bugs 2003-11-13
Anonymous
Proposed: a Bounty for Bugs 2003-11-13
Sunil James - Director, iDEFENSE
Proposed: a Bounty for Bugs 2003-11-14
Administrator
Proposed: a Bounty for Bugs 2003-11-14
Anonymous
Proposed: a Bounty for Bugs 2003-11-15
Anonymous (1 replies)
Proposed: a Bounty for Bugs 2003-11-18
intruder
Proposed: a Bounty for Bugs 2003-11-18
Anonymous
Old idea ... 2003-11-19
Garry







 

Privacy Statement
Copyright 2008, SecurityFocus