Google and Mozilla bug bounties don't buy much more security

JMH

Banned
Local time
1:40 PM
Messages
6,448
Browser bugs are too prevalent and malicious hackers are too tenacious for higher monetary rewards to make a big difference

Both Mozilla and the Google are raising their rewards for submitted critical vulnerabilities in respective browsers. Mozilla is now paying $3,000 for Firefox bugs and the Google Chromium team is paying $3133.70 ("elite" in hacker leet-speak) for bugs in Chrome, compared to the initial $1,337 reward from six months ago. Ignoring Google's cheesy figure, it's a good time to ask again if paying for bugs makes the Internet any safer. I like the idea of paying bug finders for their work, but I'm doubtful it will protect users significantly in the long run. As a matter of fact, I'm pretty sure it won't.


Google's program itself is obviously successful, enriching bug reporters and helping Google better secure its browser. Google has reported 60 vulnerabilities so far this year alone: 25 from June 9 through July 6 for Chrome 5.x and 35 from January through May in Chrome 4.x. That's far more than those found in the other two major browsers: Microsoft's Internet Explorer 8 has 27 reported vulnerabilities this year and Mozilla Firefox 3.6 has 46.
More -
Google and Mozilla bug bounties don't buy much more security | Security Central - InfoWorld
 

My Computer My Computer

At a glance

Win 7 Ultimate 64-bit. SP1.Intel i7 -720QM.[1.6GHz Turbo Boost 2.8GHz. 6...8 DDR 3 RAM. 1066MHZATI 1024 MB. DDR3. Radeon HD5650
Computer Manufacturer/Model Number
LAPTOP. HP Pavilion dv7-4010TX .
OS
Win 7 Ultimate 64-bit. SP1.
CPU
Intel i7 -720QM.[1.6GHz Turbo Boost 2.8GHz. 6MB Cache.]
Memory
8 DDR 3 RAM. 1066MHZ
Graphics Card(s)
ATI 1024 MB. DDR3. Radeon HD5650
Monitor(s) Displays
17.3" High Definition Brightview LCD. LED Backlit.
Screen Resolution
1600 x 900.
Hard Drives
640GB
Case
Laptop / notebook.
Mouse
Logitech Anywhere mouse. MX.
Internet Speed
ADSL [ but too slow ]
Back
Top