Jul 13 2007

Find A Bug – Make Some $$$

Just read a BBC news article, that reports how researchers/hackers (depending upon your viewpoint) can now make money by selling the details of any security loopholes they find. Rather than doing dodgy back room deals with dodgy criminals, the idea is that the software company that makes the buggy software can pay for good information that will then lead to their products becoming more secure.
Assuming that the auction house does actually ensure that people buying the secrets are intending to fix problems, not exploit them, this seems like a really good idea. So, as it has been a while since we’ve had a debate in the comments section on this blog, does anyone have anything to add?

