All computer programs and software have failures.The important thing is to detect and correct them in time.No matter how much time has been spent testing with programs or systems, the truth is that, when they go on the market, failures are always reported.The same goes for online applications and services: they have problems that need to be solved, which is why large companies reward bug hunters , which help them correct problems with their systems and applications.
The most juicy rewards are those that can compromise the security of the systems, so they are the ones that attract the attention of a greater number of researchers.Within them there are two types: those that focus on the problem search with a very technical approach, and then there are those who try to think like the bad ones .
The company Bugcrowd has a list with the main companies that offer some kind of reward and the type in question.In this sense, it can be an honorable mention or enter into what they call the "Hall of fame" of the company, loot or reward, which are usually monetary and depend on the amount offered.The truth is that is usually paid based on the importance of the failures found .
The Google hackaton
Google has recently presented a Hackaton for Android , called Project Zero, in which researchers who manage to find vulnerabilities in the company's operating system are eligible for a prize of 200,000 dollars.a prize of 100,000 and 50,000 dollars the second and third.
The objective is to see to what extent an investigator can find vulnerabilities, but also see how bad boys operate when discovering them, what paths they follow, etc.For this, all participants need Deliver a technical document detailing how you found the problem.
Microsoft, its Insiders program and the rewards for Bugs hunters
To debug its updates and new operating systems, Microsoft has a program called Insiders.Those enrolled in it can try the news of the Redmond company in exchange for reporting usage reports, which will serve to detect possible problems before removing it to production.In spite of this great program of betatesters , other problems can occur.I nsiders is focused on finding bugs that affect the operation of systems and programs .
The Windows developer has generously rewarded those who have made some security discovery or contribution. Offers up to 100,000 dollars to those who find security errors that put their software at risk This is the case of James Forshaw, a researcher at the British company Context Information Security, who took the reward for finding an error that skipped some protections included in the previous version of Windows 8.1.
Vasilis Pappas, a student who was a student at Columbia University at the time, took about $ 200,000 to design an innovative security prototype to prevent the exploitation of memory security vulnerabilities in Windows applications.
Facebook also rewards hackers and bug hunters
Facebook has paid more than a million dollars in bug hunter rewards.An example of this is Reginaldo Silva, a systems engineer from Brazil who found one of the worst vulnerabilities within the software from Facebook, achieving a reward of $ 30,000.
This happened as a result of the publication of a letter in the profile of Mark Zuckerberg by an investigator who did not want to pay to find this vulnerability of the service.looking for rewards.On an economic level, the truth is that a million dollars is very little for the image problems that the company may have if the vulnerability is published.
United Airlines pays with airline miles to report bugs
In other cases, companies pay in kind, that is, in what they sell.If United Airlines operates, which rewards with air miles, that is, with free trips, to those investigators who report bugs.The scale ranges from 50,000 miles for a low-level error, going through 250,000 for reporting personal data leaks or the leap of authentication and up to 1,000,000 miles for more serious vulnerabilities.
Apple's policy change in bug hunter rewards
A striking case is that of the Cupertino company, which did not reward the hunters of bugs, but recently this policy has changed offering up to 200,000 dollars for finding security problems in its applications and system This means greater security for users, as vulnerabilities found in both iOS and their desktop system will be adequately rewarded and, more importantly, patched.
The truth is that the work of the security researcher has a lot to do with analytics.The reward is only seen at the time of finding the problem, but the amount of hours behind analyzing code and the behavior of the programs It is immense, and in many cases the access to the source code of the programs is not available for researchers, which also complicates their work.
Comments
Post a Comment