Breaking News

PlayStation Plus Game Catalog for May 2025 ASUS Republic of Gamers Announces Strix OLED XG32U Series GIGABYTE AORUS MASTER 16 AI PC Wins COMPUTEX 2025 Best Choice Award addlink Virtual Showcase 2025: Explore what’s our next in storage SAMA Unveils New Gaming PC Hardware at COMPUTEX 2025

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Google To Reward Researchers Who Discover Open-source Code Security Holes

Google To Reward Researchers Who Discover Open-source Code Security Holes

Enterprise & IT Oct 10,2013 0

Google said Wednesday it plans to reward developers for developing proactive security improvements for some of the most widely used open-source software programs. Rewards will range between US$500 to $3,133.70. Google says that its Vulnerability Reward Program is not an OSS bug-hunting program. It provides financial incentives for "down-to-earth, proactive improvements that go beyond merely fixing a known security bug," according to Michal Zalewski of Google's Security Team.

"Whether you want to switch to a more secure allocator, to add privilege separation, to clean up a bunch of sketchy calls to strcat(), or even just to enable ASLR - we want to help!," he said.

Google will roll out the program gradually, based on the quality of the received submissions and the feedback from the developer community. For the initial run, Google will imit the scope to the following projects:

- Core infrastructure network services: OpenSSH, BIND, ISC DHCP
- Core infrastructure image parsers: libjpeg, libjpeg-turbo, libpng, giflib
- Open-source foundations of Google Chrome: Chromium, Blink
- Other high-impact libraries: OpenSSL, zlib
Security-critical, commonly used components of the Linux kernel (including KVM)

But Google intends to soon extend the program to widely used web servers (Apache httpd, lighttpd, nginx), SMTP services (Sendmail, Postfix, Exim), Toolchain security improvements for GCC, binutils, and llvm as well as to the OpenVPN.

In order to qualify, patches must first be submitted directly to the maintainers of the project, and researchers must work with them to have it accepted into the repository and incorporated into a shipping version of the program. After these prerequisites are met, they should submit their entry to security-patches@google.com.

Rewards for qualifying submissions will range from $500 to $3,133.7. The final amount is always chosen at the discretion of the reward panel and is based on our judgment of the complexity and impact of the patch.

Tags: Google
Previous Post
Samsung To Add Fingerprint Sensor To Next Version Of Galaxy Note 3
Next Post
T-Mobile International Options to Include Free Data Roaming

Related Posts

  • Elevate your gameplay across mobile and PC

  • What’s new in Android 15, plus more updates

  • NVIDIA Teams Up With Google DeepMind to Drive Large Language Model Innovation

  • Google at CES 2024

  • Google introduces Gemini AI model

  • Google Cloud Launches AI-Powered Anti Money Laundering Product for Financial Institutions

  • Connecting all things Android at MWC Barcelona

  • Mercedes-Benz and Google Join Forces to Create Next-Generation Navigation Experience

Latest News

PlayStation Plus Game Catalog for May 2025
Gaming

PlayStation Plus Game Catalog for May 2025

ASUS Republic of Gamers Announces Strix OLED XG32U Series
Gaming

ASUS Republic of Gamers Announces Strix OLED XG32U Series

GIGABYTE AORUS MASTER 16 AI PC Wins COMPUTEX 2025 Best Choice Award
Consumer Electronics

GIGABYTE AORUS MASTER 16 AI PC Wins COMPUTEX 2025 Best Choice Award

addlink Virtual Showcase 2025: Explore what’s our next in storage
Enterprise & IT

addlink Virtual Showcase 2025: Explore what’s our next in storage

SAMA Unveils New Gaming PC Hardware at COMPUTEX 2025
Cooling Systems

SAMA Unveils New Gaming PC Hardware at COMPUTEX 2025

Popular Reviews

be quiet! Light Loop 360mm

be quiet! Light Loop 360mm

be quiet! Dark Rock 5

be quiet! Dark Rock 5

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

G.skill Trident Z5 Neo RGB DDR5-6000 64GB CL30

G.skill Trident Z5 Neo RGB DDR5-6000 64GB CL30

Arctic Liquid Freezer III 420 - 360

Arctic Liquid Freezer III 420 - 360

Crucial Pro OC 32GB DDR5-6000 CL36 White

Crucial Pro OC 32GB DDR5-6000 CL36 White

Crucial T705 2TB NVME White

Crucial T705 2TB NVME White

be quiet! Light Base 600 LX

be quiet! Light Base 600 LX

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed