, 2003-11-10
Instead of paying hard cash to punish computer criminals, vendors should reward grey hat hackers for responsibly finding and reporting the security holes that make cyber attacks possible.
Expand all |
Post comment
|
Proposed: a Bounty for Bugs
, 2003-11-10 Instead of paying hard cash to punish computer criminals, vendors should reward grey hat hackers for responsibly finding and reporting the security holes that make cyber attacks possible.
Expand all |
Post comment
|
|
|
Privacy Statement |
Explain to me please how this is different from the current situation where you get nothing for the discovery. If I follow your logic there would be no real reason to disclose the information because the discoverer gets nothing in return, except the credits. At least now when you get some cash in return, this might convince a cash starved grey hat that it is more sure and more profitable to report the bug than to steal a couple of creditcard numbers with the new found vulnerability.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/columns/197/23664#23664