Advertisement
Promo

Security threats Toolkit

Mozilla gives bug hunter $2,500

Dan Ilet ZDNet.co.uk

Published: 31 Mar 2005 13:05 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The Mozilla Foundation has given $2,500 (£1,328) to a security researcher for discovering vulnerabilities in its free Web browser.

The company paid $500 to German researcher Michael Krax for each of the five bugs he found in Firefox.

"We developed the bug bounty programme to encourage and award community members who identify unknown bugs in the software," said Chris Hofmann, director of engineering for the Mozilla Foundation. "This programme is one of the many ways the Mozilla Foundation produces safe and secure software for its users."

The National Infrastructure Coordination Centre earlier this month posted alerts about the bugs, which relate to chrome privileges — a mechanism that allows applications to change user interface details of the browser itself. If abused, this function could alter the 'Home' button, for example, to make it download malicious programs.

Mozilla is one of the few organisations to offer financial incentives to people who find vulnerabilities. Microsoft, which charges for its products and regularly asks the user community to test beta versions of its software, has no such scheme.

A spokesperson for Microsoft said: "We don't pay people to find bugs, but there are other ways we try to fix security as much as possible. But we can't comment on what Mozilla does."

Microsoft also highlighted its cash-reward scheme for informants who help law enforcement agencies to convict virus writers.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
89 out of 182 people found this useful


Company/Topic Alerts

Create a new alert from the list below:




Video icon

Video

Sentry Posts Blog

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters