Please fill in the field below to receive your profile link.
ADVERTISEMENT
Microsoft rules out bounties for security exploits
No bucks for bugs
Iain Thomson at Infosecurity Europe 2007, vnunet.com24 Apr 2007
ADVERTISEMENT
Microsoft
has ruled out paying security researchers bounties for exploits, as practised by
other industry firms.
Speaking to
vnunet.com
at
Infosecurity
2007 Microsoft chief security advisor Roger Halbheer ruled out making
payments to researchers who discover vulnerabilities.
Instead the company wants to work with security researchers and credit them
in monthly updates.
"I do not think paying is a healthy idea," he said. "We run a researcher
conference at Redmond, called Bluehat, and once researchers see how we work they
will start to trust us. After all, we are not lazy over fixes, but patches are
very complex to develop."
Halbheer explained that it can sometimes take several hundred days to build a
patch, in part because of a long testing process. For example, a patch for the
IE browser has to go through over 400 tests before being released.
Microsoft has not been averse to using bounties before in specific
circumstances. Three years ago it offered a
$250,000
bounty for the author of the MyDoom worm,
and Mozilla
offers $500 and
a free T-shirt for each vulnerability found.
Others in the industry also use the tactic. The
US
Federal Trade Commission has suggested bounties of up to $250,000 for
information leading to the conviction of spammers.
The legitimate owner of porn site sex.com has put a bounty on the head of the cybersquatter who he claims stole his domain name and then absconded without paying damages. 31 May 2001
Welwyn Garden City, Hertfordshire, United Kingdom | Tesco.com
Subject Matter Expert - Welwyn Garden City Who's behind the world's most successful online retailer? Just over 10 years ago we started Tesco.com (aka Dotcom). Today, we've an incredible 750,000 active customers and sales at ... more >
Chichester, West Sussex, United Kingdom | West Sussex County Council
Application Support Specialists £26,449 - £28,723 pa (includes Market Rate Supplement) ChichesterIT Services at West Sussex County Council supports and manages a variety of systems that include third party and bespoke applications as well as ... more >
Shinfield Park, Reading, United Kingdom | Foster Wheeler
Our UK-headquartered operations employ more than 6,000 people and we are seeking qualified and experienced IT professionals to work in our head office in Reading, Berkshire. We are currently seeking an Analyst Programmer to join ... more >
Welwyn Garden City, Hertfordshire, United Kingdom | Tesco.com
Database Developer - Welwyn Garden CityWho's behind the world's most successful online retailer? Just over 10 years ago we started Tesco.com (aka Dotcom). Today, we've an incredible 750,000 active customers and sales at just under ... more >More job opportunities