Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Proposed: a Bounty for Bugs
Mark Rasch, 2003-11-10

Instead of paying hard cash to punish computer criminals, vendors should reward grey hat hackers for responsibly finding and reporting the security holes that make cyber attacks possible.

Submit Comment Mode:
Name:
Subject:
Message:
 
  Enter the characters that appear above
 
Proposed: a Bounty for Bugs: A Notoriously Bad Idea 2003-11-12
Michael Sierchio

The problem with offering what amounts to
a prize for discovering and revealing a
security flaw is plainly evident: what if
the discoverer decides that the potential
reward of not disclosing the defect is greater
than the offered prize?

...

[ more ]  





 

Privacy Statement
Copyright 2008, SecurityFocus