Mozilla Awards First Security Bug Bounty Payment
Thursday September 16 2004, 01:34:24
http://www.w3reports.com

The Mozilla project announced the first payments awarded as part of its Security Bug Bounty Program to Marcel Boesch, Gael Delalleau, Georgi Guninski, and Mats Palmgren, the first researchers and security experts to find and report qualifying vulnerabilities. After learning about the Security Bug Bounty Program, Mr. Delalleau, a security expert for Zencom Secure Solutions, inspected the Mozilla source code for security vulnerabilities, eventually finding a potential problem in Mozilla's email component. Commented Mr. Delalleau: "I found that the overall quality of the code is quite good. I audited other parts of Mozilla's tree without finding anything, before focusing on the POP3 code." For each critical security issue identified, the Mozilla Foundation paid out a $500 bounty. One of the award winners, Mr. Palmgren, has generously donated his award back to the Foundation to support future bounty payments.
The initial response to the Security Bug Bounty Program confirms that the transparency of Mozilla's open source model makes applications such as Firefox more secure. The open source community is able to expose potential security vulnerabilities and quickly fix them, before they are exploited by malicious hackers.
More than 400 community members have contributed over $10,000 in donations to the Security Bug Bounty Program since it was announced on August 2, supplementing start-up funding by Mark Shuttleworth and Linspire.
The Mozilla Foundation is inviting researchers and security experts to audit its software for security vulnerabilities on an ongoing basis, and is encouraging its users to continue to make donations to support this important effort. More information about the Security Bug Bounty Program is available at www.mozilla.org/security/.
Viewed 4625 times.
Copyright © 2004-2007 Press Release. All Rights Reserved.
Print
Add A Comment
Comments
Link This Article
| Preview: Mozilla Awards First Security Bug Bounty Payment |