Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Proposed: a Bounty for Bugs
Mark Rasch, 2003-11-10

Instead of paying hard cash to punish computer criminals, vendors should reward grey hat hackers for responsibly finding and reporting the security holes that make cyber attacks possible.

Submit Comment Mode:
Name:
Subject:
Message:
 
  Enter the characters that appear above
 
Proposed: Pay for non-disclosure 2003-11-17
Anonymous
Why don't the researchers come up with an estimate of the value of their exploit.

Then they contact the vendor and say, "I have discovered a new exploit against your software. I realize it takes time to repair such things and I am willing to withold disclosure for $100 per day, negotiable. I will...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus