Slashdot Mirror


VeriSign Puts Flaw Bounty on Vista and IE7

rchris1172 writes "VeriSign's iDefense Labs has placed an $8,000 bounty on remote code execution holes in Windows Vista and Internet Explorer 7. As part of its its controversial pay-for-flaw VCP (Vulnerability Contributor Program), iDefense said it will pay the reward for each submitted vulnerability that allows an attacker to remotely exploit and execute arbitrary code on either of the two Microsoft products. In addition to the $8,000 award for the flaw, iDefense will pay between $2,000 and $4,000 for working exploit code that exploits the submitted vulnerability."

6 of 91 comments (clear)

  1. Economics 101 or Why I Love Bounties by WillAffleckUW · · Score: 4, Funny

    1. Put bounty of $8000 on bugs for Vista and IE7.

    2. Get friend to go work at MSFT.

    .

    4. PROFIT!

    --
    -- Tigger warning: This post may contain tiggers! --
    1. Re:Economics 101 or Why I Love Bounties by Atario · · Score: 4, Funny

      --------joke------------>

            O
           /|\      <--- you
            |
           / \

      --
      "A great democracy must be progressive or it will soon cease to be a great democracy." --Theodore Roosevelt
  2. Moar money by zecg · · Score: 5, Funny

    "In addition to the $8,000 award for the flaw, iDefense will pay between $2,000 and $4,000 for working exploit code that exploits the submitted vulnerability."

    The company spokesman also added they'll double the bounty if the submitter already used the exploit to build a botnet and triple it if promises to use it to send a metric assload of e-mails with the subject "ha-ha" to everyone@microsoft.com.

    --
    .i lu doi ringos.star. xu do puku'aroroi dunli dopecaku leni virnu li'u
  3. NOT the best business move! by Arthur+Dent+'99 · · Score: 5, Funny

    Paying $8000 for each exploitable security flaw in Microsoft products is a quick way to put a company into bankruptcy! I noticed that the bounty only applies to the first six submissions, though, so VeriSign is only out $48000.

    Who else here thinks that VeriSign will then turn around and sell the winning entries to the black market for $50000 each? hehe

  4. The law on unintended consequences by andersen · · Score: 4, Funny

    Pointy Haired Boss: Our goal is to write bug-free software. I'll pay a ten dollar bonus for every bug you find and fix.
    Dilbert: Yahoo!
    Alice: We're rich
    Wally: Yes!!! Yes!!! Yes!!!
    Pointy Haired Boss: I hope this drives the right behavior.
    Wally: I'm gonna write me a new minivan this afternoon!

    http://www.ourlocalstyle.com/images/uploadImages/2 006/05/13/dilbert_bugFixMinivan.gif

    --
    -Erik -- --This message was written using 73% post-consumer electrons--
  5. Re:Wonder what they're really worth? by Anonymous Coward · · Score: 5, Funny

    Too bad I have this silly fear of death Yeah I wouldn't mess around with those Verisign guys either.....