Facebook one of the three most visited site is set to announce
today a bug bounty program in which researchers will benefit for reporting security holes on the popular social-
networking website.
In What Ways Will The Researcher Benefit?
Compensation, which starts at $500 and has no maximum set, will be paid only to
researchers who follow Facebook's
Disclosure Policy and agree not to go public with the vulnerability information until Facebook has fixed the problem.
How Long Will It Take For Bug To Be Fixed?
"Basically, it's not longer than a day" to fix a bug, said the Chief Security Officer Joe Sullivan.
Facebook's Whitehat page for
security researchers says: "If you give us a reasonable time
to respond to your report before making any information public and make
a good effort to avoid
privacy violations,
destruction of data, and interruption or degradation
of our service during your research, we will not bring any lawsuit against you or
ask law enforcement to investigate you."
In What Ways Has Researchers Benefitted From Your Company?
Up until now,
researchers received
recognition on the Facebook Whitehat page, maybe some
"swag," and--if they were lucky--a job.
"Some of our best engineers
have come to work here after
pointing out security bugs on our site," like Ryan McGeehan,
manager of Facebook's
security response team, said
Alex Rice, product security lead at Facebook.
Has There Been Any Measure Taken To Ensure Adequate Security To Facebook Users?
Facebook recently hired famed
iPhone jailbreaker and Sony PlayStation 3 hacker George
Hotz, who works on security issues.
Meanwhile, Facebook is allowing security researchers a way to create test accounts
on Facebook to ensure they don't violate terms of use or impact other Facebook users,
Rice and McGeehan said.
Has This Measure Worked For Any Company Before, Have An Idear?
This is the step followed by Mozilla, which launched its bug bounty program in 2004, and Google,
which offers a bug bounty program with payments ranging from $500 to more
than $3,000 for finding Web security holes, as well as a
program specifically for Chrome bugs.
Wow! This is an opportunity which most Researchers awaits for, you want to work in Facebook? Then this could be your chance.
Let your fingers work you through to Facebook.
Your comments are important to us.
Thanks for spending quality time reading posts in this blog. Do have a wonderful moment




















No comments:
Post a Comment