Feeds

Mozilla sextuples bug bounty to $3,000

Firefox and hounds

The essential guide to IT transformation

Mozilla has increased the bug bounty it pays security researchers sixfold to $3,000.

The move is designed to enlist more interest and support from flaw finders in the task of locating flaws in the code of Firefox and other software applications from Mozilla. Previously payments for eligible flaws in Firefox and Thunderbird earned just $500, under a bug bounty program first launched six years ago.

Eligible flaws need to be both critical and remotely exploitable. Payments are restricted to original security discoveries and exclude flaws in third-party plug-ins or browser extensions, however serious they might be. In addition, the scheme has been extended to cover vulnerabilities in Mozilla Mobile as well as Firefox and Thunderbird.

"For new bugs reported starting July 1st, 2010 UTC we are changing the bounty payment to $3,000 US per eligible security bug," explained Lucas Adamski, director of security engineering at Mozilla, in a blog post. "A lot has changed in the 6 years since the Mozilla program was announced, and we believe that one of the best way to keep our users safe is to make it economically sustainable for security researchers to do the right thing when disclosing information."

Mozilla's FAQ on its bug bounty program can be found here.

Google has also established a bug bounty program, offering $500 for run-of-the-mill flaws and a leet-friendly $1,337 for critical or particularly interesting flaws in Chromium, the open source code behind its Chrome web browser.

TippingPoint's Zero Day Initiative and VeriSign's iDefense have bought vulnerabilities from researchers for some years. Payments vary but tend to top out at around $10,000. The firms use the information to add signatures to its line of intrusion prevention appliances, in the case of TippingPoint, or security services informed by early warning of upcoming security problems, in the case of VeriSign.

While marketplaces for security research potentially offer higher returns there's still scope for programs from vendors that compensate security researchers for the time and effort needed for the tricky and skilled business of identifying and reporting software vulnerabilities. ®

Next gen security for virtualised datacentres

More from The Register

next story
e-Borders fiasco: Brits stung for £224m after US IT giant sues UK govt
Defeat to Raytheon branded 'catastrophic result'
Germany 'accidentally' snooped on John Kerry and Hillary Clinton
Dragnet surveillance picks up EVERYTHING, USA, m'kay?
Snowden on NSA's MonsterMind TERROR: It may trigger cyberwar
Plus: Syria's internet going down? That was a US cock-up
Who needs hackers? 'Password1' opens a third of all biz doors
GPU-powered pen test yields more bad news about defences and passwords
Think crypto hides you from spooks on Facebook? THINK AGAIN
Traffic fingerprints reveal all, say boffins
Rupert Murdoch says Google is worse than the NSA
Mr Burns vs. The Chocolate Factory, round three!
Microsoft cries UNINSTALL in the wake of Blue Screens of Death™
Cache crash causes contained choloric calamity
prev story

Whitepapers

5 things you didn’t know about cloud backup
IT departments are embracing cloud backup, but there’s a lot you need to know before choosing a service provider. Learn all the critical things you need to know.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.
Rethinking backup and recovery in the modern data center
Combining intelligence, operational analytics, and automation to enable efficient, data-driven IT organizations using the HP ABR approach.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.