VeriSign Puts Flaw Bounty on Vista and IE7
rchris1172 writes "VeriSign's iDefense Labs has placed an $8,000 bounty on remote code execution holes in Windows Vista and Internet Explorer 7. As part of its its controversial pay-for-flaw VCP (Vulnerability Contributor Program), iDefense said it will pay the reward for each submitted vulnerability that allows an attacker to remotely exploit and execute arbitrary code on either of the two Microsoft products. In addition to the $8,000 award for the flaw, iDefense will pay between $2,000 and $4,000 for working exploit code that exploits the submitted vulnerability."
Only 8k for bugs which go on the market for 15-100k each exploit? Surely you jest, no self righteous will go for such a scam.
1. Put bounty of $8000 on bugs for Vista and IE7.
2. Get friend to go work at MSFT.
.
4. PROFIT!
-- Tigger warning: This post may contain tiggers! --
While others may scoff at 8,000 dollars, people are spending hundreds of hours on projects that are bringing in much less if anything. This is a good way to give people healthy motivation and reveal vulnerabilities early...before they make headlines.
So, not so stupid. Unlike most of the posts on this article so far.
clifgriffin > blog
"In addition to the $8,000 award for the flaw, iDefense will pay between $2,000 and $4,000 for working exploit code that exploits the submitted vulnerability."
The company spokesman also added they'll double the bounty if the submitter already used the exploit to build a botnet and triple it if promises to use it to send a metric assload of e-mails with the subject "ha-ha" to everyone@microsoft.com.
Didn't you read the fine print... current/former Microsoft employees not allowed. Otherwise, every anonymous coward at Microsoft would get the same idea and sabotage Vista/IE7 to collect the reward. Crime isn't supposed to pay if you're non-monopolist!
iDefense ask you to provide all your background information, names, addressess, telephones, photocopies of IDs, etc. Most people who can find vulnerabilities will not be willing to sacrifice their privacy. When iDefence and alike will only ask for e-mail address to paypal funds to, I'd be first in line to talk to them.
$8000 might sound like a lot until you compare it to the stories we see of vulnerabilities being sold for $50,000 on underground sites. Why should I sell my findings to them for a much smaller amount?
0*0
00*
***
If you read TFA you would see that they are only offering 6 8K rewards, its not unlimited, you cannot make trillions.
have you seen my sig? there are many others like it but none that are the same
Paying $8000 for each exploitable security flaw in Microsoft products is a quick way to put a company into bankruptcy! I noticed that the bounty only applies to the first six submissions, though, so VeriSign is only out $48000.
Who else here thinks that VeriSign will then turn around and sell the winning entries to the black market for $50000 each? hehe
Pointy Haired Boss: Our goal is to write bug-free software. I'll pay a ten dollar bonus for every bug you find and fix.
2 006/05/13/dilbert_bugFixMinivan.gif
Dilbert: Yahoo!
Alice: We're rich
Wally: Yes!!! Yes!!! Yes!!!
Pointy Haired Boss: I hope this drives the right behavior.
Wally: I'm gonna write me a new minivan this afternoon!
http://www.ourlocalstyle.com/images/uploadImages/
-Erik -- --This message was written using 73% post-consumer electrons--
I'd like to think not everyone involved in the "field" is a scumbag criminal in cahoots with the Russian mafia. Go ahead, prove me wrong! Despite the seemingly faceless nature of corporations, it's always human beings like you and me that get screwed in the end.
Frankly, I prefer the company of nitwits.
And get paid for it??
Hax0r1ng is getting better all the time!
And they said we were just a bunch of internet hooligans.
muahahhaha
Microsoft is in the habit of knowing about bugs but won't fix because if it's not out in the wild.
:)
They could turn in bugs they already know about
What a cheap publicity stunt.
A 0day of this kind is worth at least twice that on the black market, mostly to the botnet creators who are the base of all the spam we get.
Assorted stuff I do sometimes: Lemuria.org
...both Apple and Cisco are suing VeriSign for the use of iDefense in the name of their labs. Apple claims that it dilutes their brand identity, and Cisco claims that they've been selling "defense" hardware with the "i" trademark for years!
"perhaps the simply righteous will step up"
Yeah, and "the righteous" could code, then there wouldn't be any exploits in the first place. 8-).
-- Terry
Some are working with the Russian military.