Wednesday, August 31, 2011

Facebook pays security bug bounty hunters $40,000 in three weeks


Facebook has revealed its security bug bounty initiative has paid out more than $40,000 in just three weeks.

 

But the social networking firm has not revealed how many security vulnerabilities have been reported or how many have been fixed.

Facebook has joined a growing list of large software firms and internet service providers who reward researchers for finding security vulnerabilities.

The basic rate is $500 for each vulnerability, but Facebook has indicated it is willing to pay more if the discovered flaw is a major one.

One bug hunter, for example, has received more than $7,000 for six different issues, while another was paid $5,000 for a single report, according to ZDNet.

Despite the success of the bug bounty initiative, Facebook has no plans to extend it to include Facebook apps and websites with Facebook plug-ins, because that could involve hundreds of thousands of third-parties.              More