More than 1 in 10 Mozilla bug finders refuse cash reward

Posted on Monday, August 09 2010 @ 0:50 CEST by Thomas De Maesschalck
Yahoo News reports between 10 and 15 percent of the bug hunters that report vulnerabilities to Mozilla refuse cash bounties:
Between 10 percent and 15 percent of the serious security bugs reported since Mozilla launched its bug bounty program have been provided free of charge, according to Mozilla. "A lot of people would say, 'Don't worry about it. Donate it to the EFF [Electronic Frontier Foundation] or just send me a T-shirt,'" said Johnathan Nightingale, the director of Firefox development, in a recent interview.

Mozilla was a pioneer in this area. It started offering a US$500 bounty for security bugs in August 2004. Since then, it's had more than 120 bugs reported by about 80 researchers. The project recently upped its bounty and is now paying out a maximum of $3,000 for critical security bugs. A few weeks later, Google announced that it, too, would pay up to $3,000 for security bugs reported in its products.

"It's been a really successful program for us. We're really happy with it," Nightingale said.


About the Author

Thomas De Maesschalck

Thomas has been messing with computer since early childhood and firmly believes the Internet is the best thing since sliced bread. Enjoys playing with new tech, is fascinated by science, and passionate about financial markets. When not behind a computer, he can be found with running shoes on or lifting heavy weights in the weight room.



Loading Comments