3 ms·
This sort of thing is not new. I think the first one was qmail: http://cr.yp.to/qmail/guarantee.html http://cr.yp.to/qmail/guarantee.html followed shortly by dj
by dpkendal 14y ago
This sort of thing is not new. I think the first one was qmail: http://cr.yp.to/qmail/guarantee.html http://cr.yp.to/qmail/guarantee.html followed shortly by djbdns: http://cr.yp.to/djbdns/guarantee.html http://cr.yp.to/djbdns/guarantee.html (which was awarded in 2009: http://article.gmane.org/gmane.network.djbdns/13864 http://article.gmane.org/gmane.network.djbdns/13864)
Dovecot also has a similar guarantee: http://dovecot.org/security.html http://dovecot.org/security.html
As does Mozilla:
http://www.mozilla.org/security/bug-bounty.html http://www.mozilla.org/security/bug-bounty.html
Even Facebook is in on the game: http://www.facebook.com/whitehat/bounty/ http://www.facebook.com/whitehat/bounty/
Bug bountying in general of course started with Donald Knuth: http://en.wikipedia.org/wiki/Knuth_reward_check http://en.wikipedia.org/wiki/Knuth_reward_check and has recently become moderately popular as a strategy for increasing open-source code quality: http://www.daemonology.net/blog/2011-09-05-lessons-learned-from-bountying-bugs.html http://www.daemonology.net/blog/2011-09-05-lessons-learned-f...
- tete 14y agoAnd Chromium: http://www.chromium.org/Home/chromium-security/vulnerability-rewards-program http://www.chromium.org/Home/chromium-security/vulnerability...