Home > slashdot > The Joys of Running a Bug Bounty Program

The Joys of Running a Bug Bounty Program

February 13th, 2011 02:20 admin Leave a comment Go to comments


Trailrunner7 writes “When Barracuda Networks started its bug bounty program about three months ago, company officials weren’t exactly sure what to expect. They didn’t know whether there’d be an onslaught of submissions or the sound of crickets chirping. The reality turned out to be somewhere in the middle. Overall, the company has been getting about 10 bug reports a month, none of which has been very serious. But that doesn’t mean the program hasn’t been a success. Peck said that Barracuda also had run into the same problem that Google and others have: hackers don’t pay much attention to directions. The company set out specific parameters for what kind of vulnerabilities in which products were in scope for the rewards, but some researchers still submitted flaws that were out of bounds, including bugs in partners’ products or in the Barracuda corporate Web site.”

Source: The Joys of Running a Bug Bounty Program

Related Articles:

  1. PayPal Starts Bug Bounty Program
  2. GitHub Launches Bug Bounty Program, Offers Between $100 and $5,000
  3. The Case For a Government Bug Bounty Program
  4. Microsoft Launches $100k Bug Bounty Program
  5. Metasploit Launches Exploit Bounty Program
blog comments powered by Disqus