Hackers Find 138 Different Security Gaps In Pentagon Websites (go.com)
An anonymous reader writes from a report via ABC News: High-tech hackers brought in by the Pentagon to breach Defense Department websites were able to burrow in and find 138 different security gaps, Defense Secretary Ash Carter said Friday. The white-hat hackers were offered various bounties if they could find vulnerabilities on five of the Pentagon's internet pages. The Pentagon says 1,410 hackers participated in the challenge and that the first gap was found just 13 minutes after the hunt began. Overall, 1,189 vulnerabilities were found, though only 138 were deemed valid and unique. The experiment cost $150,000, and about half of it was paid to the hackers as bounties. The "Hack the Pentagon" program will be followed by a series of initiatives, including a process that will allow anyone who finds a security gap in Defense Department systems to report it without fear of prosecution.
but not persecution
... Snowden's phone number and stuff?
It little behooves the best of us to comment on the rest of us.
The experiment cost $150,000, and about half of it was paid to the hackers as bounties
Where did the other 75 kUSD half go? Paid to a contractor for creating the vulnerability report web form?
138 vulnerabilities is quite a low number. This is going to do nothing but give them a false sense of security.
"I don't know, therefore Aliens" Wafflebox1
Anyone who succeeded at this game...congrats, you're now under 24/7 surveillance by the FBI. Was it worth the 325 dollars per exploit? (75,000 in prize money, divided by 138, then take taxes out at a 40% rate).
Like the FBI, some of those hackers will NOT report the vulnerability, and ask for more money from other governments... Way tio go Pentagon -- I suggest the government hire and train their own hackers - when the FBI has to pay Israel to unlock an iPhone it shows we are falling way behind where we ought to be when it comes to security of any kind. We used to be #1, now we are #16.
1,410 more people added.
What? No obligatory XKCD yet!? https://xkcd.com/932/
Security the the fastest growing field in IT in the US, and one of the fastest growing overall. My salary is four times what it was five years ago.
My first thought was the same as yours. On our last PCI ASV test we found something like 8,000 exposures or more. But then I remembered the Pentagon thing is only for specific web pages. Also 138 UNIQUE ones - five instances of similar injections exposures count as one.
just saying ...they did not report them all apparently ....and i aint here to help them
In summary, the participants were stolen collectively 1 million dollars in exchange of 75 000 dollars. When will CS people start to understand their own work worth something better than the f... peanuts given in such f... events?
Achille Talon
Hop!
The government hiring common criminals now? They used to be at least some sort of classy.
Sure - if you are established in your field, then you can command the big bucks. But to achieve a payout like this if you are a college student would make your resume SHINE. It'
They found 138 security gaps? So apparently they only tested 138 sites. :)
This is like dipping a cup in the ocean 10 times and reporting that you "found 10 cups of water in the ocean".
Just cruising through this digital world at 33 1/3 rpm...
An anonymous reader writes from a report via ABC News
American Broadcasting Company
The white-hat hackers were offered various bounties if they could find vulnerabilities on five of the Pentagon's internet pages.
In other words they were paid. Paid by who? Tax payers.
Come to find out for about $75,000 (half of 15) they found out tax payers' money so far has only given them a pwned network at the DoD.
Meanwhile, they control all the spyware from Google tracking to Microsoft closed source spyware to Facebook profiling. They have employees paid by tax payers that try to hack the planet's networks 24/7. "Friend of Israel" they say.
The government needs to recruit some of these hackers to both find our vulnerabilities and attack hostile websites like ISIS. The only question is what should their pay rate or GSA status be? Obviously some of these folks are a lot smarter than our current government security workers, so their pay grade should be higher.