Brand new Google Instant: a search-as-you-type engine and Google SG will soon get a taste of it. See http://bit.ly/cm7kzy and @zdnetasia
12 minutes ago by jamieyzdnetasia on twitterZDNet is available in the following editions:
Google latest addition to tech vendors offering security researchers monetary rewards for vulnerabilities uncovered, but rest of industry not likely to follow suit.
More software businesses are now offering a bounty to security researchers, or whitehats, to uncover and disclose vulnerabilities but it remains to be seen if other vendors are willing to take that approach.
Efforts to pay security researchers for reporting vulnerabilities in software are not new. Back in 2002, iDefense introduced its Vulnerability Contributor Program, while the Mozilla Foundation in 2004 said it would pay US$500 for each serious bug identified in its browser. TippingPoint in 2005 launched its Zero Day Initiative (ZDI), pledging to pay hackers that report security vulnerabilities.
Last week, Google hopped onto the bounty bandwagon when the Internet giant rolled out its own incentive scheme for bugs identified in its Chrome browser. Crediting Mozilla for the idea, Chris Evans from Google's Chrome security team, noted in a blog post that the move was a way to recognize researchers currently active in the security industry, as well as to recruit more external contributors.
"For existing contributors to Chromium security--who would likely continue to contribute regardless--this may be seen as a token of our appreciation," Evans wrote. "In addition, we are hoping that the introduction of this program will encourage new individuals to participate in Chromium security."
"The more people involved in scrutinizing Chromium's code and behavior, the more secure our millions of users will be," he added.
Negative initial sentiments
The approach of offering a bounty for responsible disclosure of vulnerabilities was not always well received, though, some of these sentiments may have changed over time.
In an e-mail interview, Pedram Amini, manager of security research at TippingPoint, pointed out that the emergence of the whitehat market in 2002 "was for the most part, negatively received among researchers". This, he noted, has changed over the years.
"Increasingly, more and more well-respected researchers are supporting the 'no more free bugs' movement," said Amini. "These researchers point out that vulnerabilities have legitimate value and, therefore, should not be made available to vendors free-of-charge."
While he acknowledged that efforts such as the ZDI, which has to date reported 350 vulnerabilities, are unable to "compete price-wise" with the underground economy, Amini noted that selling on the "black or grey markets" requires more effort.
"Vulnerabilities sold on the black market must also come with a packaged attack ready to exploit the vulnerability," he explained. "And the price may still vary based on how easy it is to 'weaponize' the attack, and how long it can go undetected."
On the other hand, security researchers can simply send a "crash report" with basic details about the vulnerability and the ZDI team, for instance, would "do the digging to uncover the actual flaw in the code".
Will others follow?
Despite researchers increasingly calling for payment for bugs, not all vendors are prepared go down this path and "definitely not anytime soon", said Amini.
"There are some vendors who treat the [issue] with the same hostility that governments respond to [when] negotiating with terrorism--meaning, they are vehemently opposed to paying researchers for bugs," he noted.
Concurring, Ovum's principal analyst Graham Titterington, said in an e-mail the practice of paying for vulnerability disclosure is not widespread.
It is not in the vendors' interest "to uncover bugs that would otherwise remain undiscovered", simply to ensure they have the information before the hackers do because the vendors incur additional costs, Titterington noted.
He suggested that the "utopian" solution going forward is to develop higher quality or vulnerability-free codes.
Mike Reavey, director of Microsoft Security Response Center, told ZDNet Asia in an e-mail that the software vendor "does not believe offering compensation for vulnerability information is the best way we can help protect our customers". Redmond will continue with its policy to credit researchers who practise responsible disclosure of vulnerabilities, Reavey added.
"It is our belief that compensation for zero-day vulnerabilities does not foster a community-based approach to protecting customers from cybercrime," he said. "Rather, collaboration with the research community and members of the industry is essential to effective security response practices as no one individual, company or technology, can secure the Internet alone."
Microsoft has previously offered rewards, albeit on an ad-hoc basis, to support an internal Windows Vista bug-hunting effort, as well as for information leading to the identification of the creators behind worms such as Blaster and Sasser.
Brand new Google Instant: a search-as-you-type engine and Google SG will soon get a taste of it. See http://bit.ly/cm7kzy and @zdnetasia
12 minutes ago by jamieyzdnetasia on twitter#Force #Cloud S'pore: Social media trumps paid keyword ads: Microsoft aiming to hone CRM pitch: SAN FRANCISCO-... http://bit.ly/do6ECA #TCN
18 minutes ago by ForceCloud on twitterIwebslog.com-Multi-task tricks of the Table Move handle in Word: Click or double-click the Table Move handle... http://dlvr.it/4xkZW #Excel
35 minutes ago by learnexcel on topsyS'pore: Social media trumps paid keyword ads http://bit.ly/96gvyw
42 minutes ago by TheProfitCenter on twitterMicrosoft aiming to hone CRM pitch: As it gears up to start testing a new version of its product, Redmond says it'... http://bit.ly/cCRyE6
49 minutes ago by webcrmsoftware on twitter10 things you should know about NoSQL databases: The relational database model has prevailed for deca... http://bit.ly/9kJeXc - #Asia #News
50 minutes ago by AsiaTodayNews on twitterMulti-task tricks of the Table Move handle in Word: Click or double-click the Table Move handle to qu... http://bit.ly/b7UBPf - #Asia #News
50 minutes ago by AsiaTodayNews on twitterMicrosoft aiming to hone CRM pitch: SAN FRANCISCO--Microsoft is tired of seeing Salesforce.com get all the headlin... http://bit.ly/d6Uf6U
1 hour 6 minutes ago by DaisySteward on twitterMicrosoft aiming to hone CRM pitch: SAN FRANCISCO--Microsoft is tired of seeing Salesforce.com get all the headlin... http://bit.ly/9vsZxf
1 hour 6 minutes ago by henrycowell on twitterwho would've thunk it?? increasingly important medium.. 'S'pore: Social media trumps paid keyword ads' - ZDNet Asia - http://bit.ly/axe88O
2 hours 10 minutes ago by karunspeak on twitterRT @zdnetasia: Oracle's Hurd for Phillips swap: What's the customer relations impact? http://ur1.ca/1jqms
2 hours 24 minutes ago by MalAliehs on twitterSalesforce chief: Enterprise tech lacks innovation: Consumer tech makers such as Twitter are setting ... http://bit.ly/ca4KYi - #Asia #News
2 hours 53 minutes ago by AsiaTodayNews on twitterAdobe warns of zero-day hole in Reader, Acrobat: Critical vulnerability could allow an attacker to ta... http://bit.ly/bY9Xe6 - #Asia #News
2 hours 53 minutes ago by AsiaTodayNews on twitterMicrosoft aiming to hone CRM pitch http://bit.ly/dn8jno
3 hours 33 minutes ago by superstarch on topsyLink to the Dual Roles of the CIO: http://www.ciodashboard.com/cio-careers/cio-dual-roles/
12 hours 46 minutes ago by cbcurran on Boeing CIO: IT key to drive business growthHere's another view of the dual roles of the CIO that I think is consistent. What we've found, however, is that only about 1 in 4 CIOs o...
12 hours 47 minutes ago by cbcurran on Boeing CIO: IT key to drive business growthI agree with the author's sentiment in that Oracle seems to be set on a course to building an anti-open-source reputation. I don't agree ...
13 hours 51 minutes ago by sisto on Could Oracle fracture open source community?Hi Rick, I like your point that there is a time and a place for automation, and that it can be quite effective when used properly. One su...
16 hours 11 minutes ago by XebiaLabs on Agile drivers for new project management toolssorry for the double entry just a mistake
19 hours 22 minutes ago by notek on 5 ways to avoid removable media malwareAmazing and very informative blog one point i'd like to point out is that, for number 2 instead of completely restraining the use of remo...
19 hours 23 minutes ago by notek on 5 ways to avoid removable media malwareS'pore: Social media trumps paid keyword ads http://bit.ly/9Z7dNd
19 hours 40 minutes ago by lenwilton on topsyHi. My name is Philippe de Passorio, head of Total Immersion office in Apac. Since we have opened our subsidiary in Hong Kong 1 year ago,...
20 hours 25 minutes ago by philippe on APAC lags in augmented reality adoptionHaha, thought long and hard about how to phrase it... no worries, you owe me lunch then, ;)
23 hours 26 minutes ago by yedwin on Is M'sia's online world ready for free speech?Nice post man. Looks like I don't have to write one on this now.
23 hours 48 minutes ago by davidlian on Is M'sia's online world ready for free speech?The only reason Oracle has a leg to stand on here is that Sun didn't open source all of Java. The saw that Java as a desktop application...
1 day 30 minutes ago by txtechdog on Could Oracle fracture open source community?I recently made some good experiences with CopyRight2 from Sys-Manage. You can download a trial version here: http://www.sys-manage.com/P...
1 day 8 minutes ago by JPatrick on Migrate shares from one Windows NT server to anotherI have to disagree with the author's statement "If Oracle destroys OpenOffice and MySQL the Linux operating system would be left with, wh...
1 day 29 minutes ago by schumacr on Could Oracle fracture open source community?Oracle may well kill OpenOffice and MySQL but the FOSS community has a better DB in PostgreSQL, and OOo will be forked to get out from un...
1 day 57 minutes ago by GreyGeek on Could Oracle fracture open source community?sir want create my own accounting software but i dont know anythink abount the programing i try to improave my self with learn of some ex...
1 day 29 minutes ago by parveenidhi on Create a shortcut to a custom Word templateFacilitating Change Through Business-Centric IT Innovation - 28 Sep 2010, Singapore
Register for Governmentware 2010 today!
Join us at Asia's Premier Infocomm Security Conference from 28 Sep - 30 Sep
Download your complimentary UPS Resource Kit!
Use these featured resources to optimize your power protection and management.
Stop Waiting Start Switching to Juniper
Free Gartner Report shows it reduces costs and increases efficiency
2010 IT Salary & Skills Report
Find out the salary range of IT professionals. Join activeTechPros for free access to the report.