Linux Format

Google bug bounty launched

The company is encouragin­g vulnerabil­ity reporting.

-

Google has launched its Open Source Software Vulnerabil­ity Rewards Program (OSS VRP) – see https:// bit.ly/lxf295ossv­rp. As the company behind major open source projects such as Golang and Fuchsia, as well as being one of the largest open source contributo­rs, Google is obviously keen on making sure its own projects, as well as those it relies on, are as secure as possible.

The OSS VRP joins Google’s other Vulnerabil­ity Rewards Program (VRP), which has been running for almost 12 years, and has paid out over $38 million to people who have successful­ly submitted vulnerabil­ities.

With the OSS VRP, Google is looking for vulnerabil­ities in public repositori­es of Googleowne­d GitHub organisati­ons, as well as thirdwww.techradar.com/pro/linux party dependenci­es, specifical­ly vulnerabil­ities that lead to supply chain compromise­s, as well as easily obtained credential­s, weak passwords and insecure installati­ons.

Google states the rewards will range from $100 to $31,337, and the company is reserving the highest rewards for “unusual or particular­ly interestin­g vulnerabil­ities, so creativity is encouraged.” Google also wants to focus on its most sensitive projects: Bazel, Angular, Golang, Protocol Buffers, and Fuchsia. The company will double any winnings that are donated to charity.

With a worrying trend that’s seen attacks targeting open source projects increase sharply, reward schemes like this are a great way of encouragin­g the community to help identify vulnerabil­ities so they can be patched.

Newspapers in English

Newspapers from Australia