Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Proposed: a Bounty for Bugs
Mark Rasch, 2003-11-10

Instead of paying hard cash to punish computer criminals, vendors should reward grey hat hackers for responsibly finding and reporting the security holes that make cyber attacks possible.

Comments Mode:
Proposed: a Bounty for Bugs 2003-11-10
researcher
Proposed: a Bounty for Bugs 2003-11-11
Anonymous (1 replies)
Proposed: a Bounty for Bugs 2003-11-13
Mark Rasch
Proposed: a Bounty for Bugs 2003-11-11
Psuedo-Anonymous Coward (1 replies)
Proposed: a Bounty for Bugs 2003-11-19
Anonymous
Proposed: a Bounty for Bugs 2003-11-11
Anonymous (1 replies)
Proposed: a Bounty for Bugs 2003-11-13
Anonymous
Proposed: a Bounty for Bugs 2003-11-11
agent1
Proposed: a Bounty for Bugs 2003-11-11
Ragnarok
Proposed: a Bounty for Bugs 2003-11-11
Theuns
Proposed: a Bounty for Bugs 2003-11-11
frustrated security dweeb
Proposed: a Bounty for Bugs 2003-11-12
Bob Weiss - Passsword Crackers, Inc.
Proposed: a Bounty for Bugs 2003-11-12
Lockdown
Proposed: a Bounty for Bugs 2003-11-12
Anonymous
Proposed: a Bounty for Bugs: A Notoriously Bad Idea 2003-11-12
Michael Sierchio (1 replies)
Proposed: a Bounty for Bugs: A Notoriously Bad Idea (NOT) 2003-11-13
Raindeer (1 replies)
Michael, you're worried what might happen if somebody values the worth of not disclosing a vulnerability higher than the reward for disclosing it to the vendor. You see this as the major flaw in the scheme.

Explain to me please how this is different from the current situation where you get nothing for the discovery. If I follow your logic there would be no real reason to disclose the information because the discoverer gets nothing in return, except the credits. At least now when you get some cash in return, this might convince a cash starved grey hat that it is more sure and more profitable to report the bug than to steal a couple of creditcard numbers with the new found vulnerability.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/197/23664#23664
Proposed: Pay for non-disclosure 2003-11-17
Anonymous
Proposed: a Bounty for Bugs 2003-11-13
Anonymous
Proposed: a Bounty for Bugs 2003-11-13
Anonymous
Proposed: a Bounty for Bugs 2003-11-13
Sunil James - Director, iDEFENSE
Proposed: a Bounty for Bugs 2003-11-14
Administrator
Proposed: a Bounty for Bugs 2003-11-14
Anonymous
Proposed: a Bounty for Bugs 2003-11-15
Anonymous (1 replies)
Proposed: a Bounty for Bugs 2003-11-18
intruder
Proposed: a Bounty for Bugs 2003-11-18
Anonymous
Old idea ... 2003-11-19
Garry







 

Privacy Statement
Copyright 2008, SecurityFocus