Start-up reignites bug-disclosure debate

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

…she came across similar situations about a dozen times during her stint at the software giant between 2000 to 2005.

"Most major vendors, including Microsoft, have strong corporate values and will not pay for vulnerabilities," Forslof said. "So, making that threat to pay me, or I'll harm your customers, is basically like extortion to them."

DeMott, however, said his company has had some success with its business model.

Over the past four months, the company has seen roughly half of potential customers agree to pay the bug bounty fee, and the other half reject the idea outright. And, in one case, a company declined to pay the bug fee but then signed up for VDA's consulting services. To date, two companies have purchased the vulnerabilities that VDA discovered and patched them, DeMott said.

But Ullrich described such customers as "paying for protection".

"There are people who pay protection to the mob. It's really a protection racket," Ullrich said. "I can't see it as a legitimate business model."

Other business models
Bug bounty hunters have a variety of means to generate income, security researchers say.

Auction site WabiSabiLabi, where software companies and security vendors bid on such discoveries, emerged on the scene recently, amid some controversy that the buyers of the vulnerabilities may be malicious attackers.

Since the Switzerland-based site was announced on 9 July, approximately 20 vulnerabilities have been posted for auction, ranging in price from 200 to 2,600 euros (£134 to £1,750), Roberto Preatoni, WabiSabiLabi's strategic director, said in an email.

"You should take into account that this market just started. Therefore, we think it's needed to wait at least six months before seeing real values being expressed in it," Preatoni said.

Three vulnerabilities have been sold on the auction site, while six more are currently on the market as their auction time ticks down.

Other compensation methods for bug hunters have included landing lucrative contracts with software vendors to debug their products, and participating in ongoing, formal bug-reporting programmes offered by TippingPoint, iDefense and the Mozilla Foundation.

:

Sentry Posts Blog

Sentry Posts Blog
Guarding the network

What you need to know — and what you and your peers have to tell us — about security management in our new community group blog

Read more +

Back in 2005, TippingPoint launched its Zero Day Initiative programme. The programme pays money to security researchers for bugs and proof-of-concept code, or working exploits they discover.

Based on the severity of the vulnerabilities and extent to which they are distributed, TippingPoint will pay researchers on a sliding scale. Forslof noted TippingPoint generally pays more if a researcher has taken the extra effort to develop proof-of-concept code.

"Based on the amount of money [DeMott] wanted for the bug and working exploit, it would have been in line with what we would have offered," Forslof said. "The amount of money he was asking for was not out of line — it's just the way he went about asking for it from LinkedIn."

Once TippingPoint buys bugs and exploits from security researchers, it then validates the information before passing it on to the software vendor for free. TippingPoint then writes filters for its intrusion-prevention devices based on the information it has validated from the bug hunter.

iDefense, which operates the iDefense Vulnerability Contributor Program (VCP), has a similar concept. The main difference is iDefense, after validating the information and notifying the software vendor for free, uses the information to notify its own client base and build workarounds until the vendor develops a patch.

"The VCP provides researchers with ways to get legally paid for the research they do," Doyle said. He noted the payments can vary from a couple of hundred dollars to as much as $10,000 (£4,914).

The Mozilla Foundation, meanwhile, offers a $500 (£245) bounty for every serious security bug found in its software.

DeMott said VDA is not wedded to its business model and may be open to tweaking it.

"If this business model is not panning out the way we had hoped, then we may focus on government or commercial contracts," DeMott said. "I certainly won't turn down a contract."

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Freebies202

Duplicate comments are not made intentionally. Its very good to know that now you are keeping check on this problem because sometimes a commenter...

4 hours ago by Freebies202 on Microsoft fixes blog comments, speeds up blogs with open source
kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

12 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

13 hours ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

14 hours ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

16 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

17 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

19 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

19 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

19 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

20 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

22 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

1 day ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

1 day ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

1 day ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

1 day ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

1 day ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint