Feeds

Mozilla sextuples bug bounty to $3,000

Firefox and hounds

The Essential Guide to IT Transformation

Mozilla has increased the bug bounty it pays security researchers sixfold to $3,000.

The move is designed to enlist more interest and support from flaw finders in the task of locating flaws in the code of Firefox and other software applications from Mozilla. Previously payments for eligible flaws in Firefox and Thunderbird earned just $500, under a bug bounty program first launched six years ago.

Eligible flaws need to be both critical and remotely exploitable. Payments are restricted to original security discoveries and exclude flaws in third-party plug-ins or browser extensions, however serious they might be. In addition, the scheme has been extended to cover vulnerabilities in Mozilla Mobile as well as Firefox and Thunderbird.

"For new bugs reported starting July 1st, 2010 UTC we are changing the bounty payment to $3,000 US per eligible security bug," explained Lucas Adamski, director of security engineering at Mozilla, in a blog post. "A lot has changed in the 6 years since the Mozilla program was announced, and we believe that one of the best way to keep our users safe is to make it economically sustainable for security researchers to do the right thing when disclosing information."

Mozilla's FAQ on its bug bounty program can be found here.

Google has also established a bug bounty program, offering $500 for run-of-the-mill flaws and a leet-friendly $1,337 for critical or particularly interesting flaws in Chromium, the open source code behind its Chrome web browser.

TippingPoint's Zero Day Initiative and VeriSign's iDefense have bought vulnerabilities from researchers for some years. Payments vary but tend to top out at around $10,000. The firms use the information to add signatures to its line of intrusion prevention appliances, in the case of TippingPoint, or security services informed by early warning of upcoming security problems, in the case of VeriSign.

While marketplaces for security research potentially offer higher returns there's still scope for programs from vendors that compensate security researchers for the time and effort needed for the tricky and skilled business of identifying and reporting software vulnerabilities. ®

Build a business case: developing custom apps

More from The Register

next story
14 antivirus apps found to have security problems
Vendors just don't care, says researcher, after finding basic boo-boos in security software
'Things' on the Internet-of-things have 25 vulnerabilities apiece
Leaking sprinklers, overheated thermostats and picked locks all online
Only '3% of web servers in top corps' fully fixed after Heartbleed snafu
Just slapping a patched OpenSSL on a machine ain't going to cut it, we're told
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Secure microkernel that uses maths to be 'bug free' goes open source
Hacker-repelling, drone-protecting code will soon be yours to tweak as you see fit
Israel's Iron Dome missile tech stolen by Chinese hackers
Corporate raiders Comment Crew fingered for attacks
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Researcher sat on critical IE bugs for THREE YEARS
VUPEN waited for Pwn2Own cash while IE's sandbox leaked
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Backing up Big Data
Solving backup challenges and “protect everything from everywhere,” as we move into the era of big data management and the adoption of BYOD.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.