Original URL: http://www.theregister.co.uk/2005/10/24/secfocus_flaw_bounty/
Security firm iDefense, a subsidiary of VeriSign, announced on Friday the recipients of two rounds of bonuses rewarding the most prolific researchers taking part in the firm's Vulnerability Contributor Program (VCP).
The researchers split $40,000 in bonuses: Three people divvied up $10,000 awarded to the top flaw finders for the quarter, while five researchers received $30,000 split among the most prolific flaw finders for the year. One researcher, identified only by his handle "infamous41md," took home an award in each category for a total of $13,000 in bonuses for the quarter.
The awards come as security researchers are still debating whether such bug bounties help make software more secure. However, despite questionable benefits, the programs are becoming more popular. In July, TippingPoint, a subsidiary of 3Com, announced its own program, the Zero-Day Initiative. And the Mozilla Foundation pays researchers who find serious security holes in its Internet browser.
This year, iDefense has published almost 120 vulnerabilities discovered by participants of the firm's flaw-finding program, according to the company's Web site.
Copyright © 2005, SecurityFocus (http://www.securityfocus.com/)
Security vuln auction site pulls in research (12 October 2007)
http://www.theregister.co.uk/2007/10/12/wslabi_update/
Linkedin spurns bug bounty hunter (31 July 2007)
http://www.theregister.co.uk/2007/07/31/fees_for_exploits/
Security flaw marketplace lays out its wares (6 July 2007)
http://www.theregister.co.uk/2007/07/06/security_flaw_marketplace/
Firm offers to patent security fixes (6 June 2007)
http://www.theregister.co.uk/2007/06/06/security_fix_patent/
Stealth techniques push malware under the radar (3 October 2006)
http://www.theregister.co.uk/2006/10/03/verisign_stealth_malware_report/
Report security vulns at your peril (25 May 2006)
http://www.theregister.co.uk/2006/05/25/security_vuln_reporting_risk/
Breach case could curtail web flaw finders (28 April 2006)
http://www.theregister.co.uk/2006/04/28/breach_suspect_prosecuted/
Groups argue over merits of flaw bounties (6 April 2006)
http://www.theregister.co.uk/2006/04/06/vulnerability_purchasing_debate/
3Com puts a bounty on vulns (25 July 2005)
http://www.theregister.co.uk/2005/07/25/3com_vuln_bounty/
VeriSign snags iDefense for $40m (14 July 2005)
http://www.theregister.co.uk/2005/07/14/verisign_buys_idefense/
$250K reward for Sasser virus informants (8 July 2005)
http://www.theregister.co.uk/2005/07/08/sasser_snitch_reward/
Blaster copycat author jailed for 18 months (31 January 2005)
http://www.theregister.co.uk/2005/01/31/blaster_kiddo_sentencing/
Mozilla to pay bounty on bugs (3 August 2004)
http://www.theregister.co.uk/2004/08/03/mozilla_bug_bounty/
Proposed: a Bounty for Bugs (18 November 2003)
http://www.theregister.co.uk/2003/11/18/proposed_a_bounty_for_bugs/
© Copyright 2008