Facebook Cyber Chief Says Bug Bounty Program is ‘Valuable’

From: The Wall Street Journal

By Rachael King, Reporter

Facebook Inc. says a unique program that pays outsiders to spot security flaws in its internal systems has proved useful for mitigating cybersecurity threats. Unlike typical bug bounty programs, which are meant to help mitigate flaws in public-facing websites, FacebookFB -1.31% also pays security researchers $500 or more for revealing bugs that enable access to a system within the company’s infrastructure. 

“It’s proven really valuable in terms of building out, in the security community, a network of people who are not just Web app penetration testers, but who are also thinking about other types of infrastructure,” said Joe Sullivan, chief security officer of Facebook Tuesday during a conference sponsored by security software vendor Kaspersky Lab.

Bug bounty programs have grown in popularity since Facebook launched its program in 2011. For example, Heroku Thursday said it had started a bug bounty program with Bugcrowd and would offer cash rewards of between $100 and $1500, depending upon the severity of the vulnerability.

Read Complete Article

Facebooktwittergoogle_plusredditpinterestlinkedinmail

Leave a Reply

Your email address will not be published.

Please Answer: *