3 ms·
No. They shouldn't. They are publicly funded so efficiency of cash flow is important. No reward should be required in this circumstance apart from perhaps an ac
by csmithuk 13y ago
No. They shouldn't. They are publicly funded so efficiency of cash flow is important. No reward should be required in this circumstance apart from perhaps an acknowledgement.
They should operate an open submission policy though i.e. a bug report form and actually feed back to people.
- aaronem 13y agoI can think of a purely utilitarian reason to offer a bug bounty: Getting paid a bounty directly by the government is easier and safer than selling an exploit to someone who will use it for criminal purposes. Granted that in an ideal world this sort of incentive wouldn't be necessary, but if we lived in an ideal world, code wouldn't have bugs in it, too. And another reason: If the government pays bounties for confirmed bug reports, a prospective reporter can have some confidence that they won't react to the report by taking punitive action, which might otherwise be a very real concern; HN periodically sees threads about employers and clients reacting extremely badly to unsolicited exploit reports, and the worst those can do stops short of imprisoning somebody. Of course, all of this assumes a government not so sclerotic that it'll take an interest in fixing bugs without first having to be motivated by a horribly embarrassing public compromise, which means it's probably not going to work in the UK, or for that matter in the US either. But it's a nice thought, I suppose.
- yerma 13y agoBut in offering a bug bounty you will effectively give the okay for anyone anywhere to attack your assets. This would remove the ability to detect or easily prosecute attackers as up to a point the bounty hunters and bad guys will look exactly the same.
- shawabawa3 13y ago> They are publicly funded so efficiency of cash flow is important Bug bounty rewards are orders of magnitude cheaper than the damage the bugs can cause. If they have a bug report form at all and employ people to screen and respond to bug reports, the bounty costs probably wont even add up to the cost of 1 additional employee
- csmithuk 13y agoDepends. In the UK we just wait for the minister in charge to resign. That's cheaper than a bug bounty :)
- yerma 13y agoI disagree, when you understand the way UK government works, any compromises will be cheaper in nearly every case along with requiring no action on their part in the first place which is even better. Planning the creation of a team to handle this will likely run in to the millions before you've even begun, that is the way it works. And noone resigns they just go in to hiding for a while ;)
- room271 13y agoDo you think that private companies that use bug bounties are being inefficient then?
- csmithuk 13y agoProbably but that's moot. They're pissing away profit and investor's cash in private companies. In public organisations, taxpayers don't get to choose if that money is spent or not.