Microsoft chief security advisor Roger Halbheer
Microsoft chief security advisor Roger Halbheer
R E L A T E D   C O N T E N T
ADVERTISEMENT

Microsoft rules out bounties for security exploits

No bucks for bugs

Iain Thomson at Infosecurity Europe 2007, vnunet.com 24 Apr 2007
ADVERTISEMENT

Microsoft has ruled out paying security researchers bounties for exploits, as practised by other industry firms.

Speaking to vnunet.com at Infosecurity 2007 Microsoft chief security advisor Roger Halbheer ruled out making payments to researchers who discover vulnerabilities.

Instead the company wants to work with security researchers and credit them in monthly updates.

"I do not think paying is a healthy idea," he said. "We run a researcher conference at Redmond, called Bluehat, and once researchers see how we work they will start to trust us. After all, we are not lazy over fixes, but patches are very complex to develop."

Halbheer explained that it can sometimes take several hundred days to build a patch, in part because of a long testing process. For example, a patch for the IE browser has to go through over 400 tests before being released.

Microsoft has not been averse to using bounties before in specific circumstances. Three years ago it offered a $250,000 bounty for the author of the MyDoom worm, and Mozilla offers $500 and a free T-shirt for each vulnerability found.

Others in the industry also use the tactic. The US Federal Trade Commission has suggested bounties of up to $250,000 for information leading to the conviction of spammers.

Security research companies Tipping Point and iDefence also use the tactic.

See also:

Zero Day Initiative offers a fist full of dollars  26 Jul 2005
Bounty on spammersFederal Trade Commission looking for junk mail 'whistleblowers'  20 Sep 2004
DVD-copying software company offers bounty in response to industry complaints  20 Feb 2003
The legitimate owner of porn site sex.com has put a bounty on the head of the cybersquatter who he claims stole his domain name and then absconded without paying damages.  31 May 2001
Internet retailer Lastminute.com has not made any of its private investors instant millionaires during its first morning of trading.  14 Mar 2000

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Greythorn IT
Leading Mobile Network vendore is currently seeking a Process consultant for a positions based either in the Middle east or Africa. We are looking for around 10 years experience with at least 5 years business ... more >
| Greythorn IT
Tier 1 Network solutions provider is currently seeking an experienced Telecommunications sales manager to work in their Abu Dhabi office. There is a brilliant benefits package as well as an attractive salary available for the ... more >
| Greythorn IT
Leading network solutions provider in Egypt is currently seeking and experienced Egyptian Network Operation /Supervision Engineer. There are competitive packages and attractive benefits package on offer for the right candidate. You will be responsible to ... more >
| Greythorn IT
A leading network Solutions vendor is currently seeking an Egyptian national to act as a Service Assurance manager out of their Egyptian office. Ideally we are looking for someone with Vendor based experience however other ... more >
More job opportunities