3 ms·
Interesting idea. Try get people who are considering selling exploits to get a little money from Google instead. Michal Zalewski (lcamtuf) is highly respected i
by casca 13y ago
Interesting idea. Try get people who are considering selling exploits to get a little money from Google instead. Michal Zalewski (lcamtuf) is highly respected in the security world - The Tangled Web and Silence on the Wire are excellent reads.
It would be very surprising if this didn't lead to a few new BIND and ISC DHCPD bugs coming out in the near future.
- 0x0 13y agoIt's a very nice program and can only lead to good things, but the relatively modest rewards aren't exactly likely to bring openssh 0days into the light :)
- WestCoastJustin 13y agoWhat's really cool about this, is that it looks like it applies to more than just security fixes i.e. Qualifying submissions - Any patch that has a demonstrable, significant, and proactive impact on the security of one of the in-scope projects will be considered for a reward. Examples include: Improvements to privilege separation, Memory allocator hardening, Cleanups of integer arithmetics, Systematic fixes for various types of race conditions, Elimination of error-prone design patterns or library calls. Reactive patches that merely address a single, previously discovered vulnerability will typically not be eligible for rewards. [1] [1] https://www.google.com/about/appsecurity/patch-rewards/ https://www.google.com/about/appsecurity/patch-rewards/
- IanCal 13y agoI suppose these are likely to be security fixes, but it's really nice to see a change in attitude. You can have fixed a security bug before anyone knows it exists by fixing up areas of code likely to contain bugs. This also widens the group of people who can submit fixes, since you can fix something that looks a bit dodgy without having to prove there is a particular exploit.