Google expands bug bounty program to include open source software

Share this article:
Google is adding open source software bugs to its vulnerability reward program.
Google is adding open source software bugs to its vulnerability reward program.

Internet technology company Google is adding bugs in open source software (OSS) to its vulnerability reward program, effectively expanding the bug bounty project that has been ongoing since November 2010.

In its initial run, Google will be offering vulnerability rewards ranging from $500 to $3,133.70 for core infrastructure network services, including OpenSSH, BIND, ISC DHCP; and core infrastructure image parsers, including libjpeg, libjpeg-turbo, libpng, giflib, according to a post by Michal Zalewski, a Google security team member.

Bug hunters will also receive vulnerability rewards for open-source foundations of Google Chrome, such as Chromium and Blink; other high-impact libraries, including OpenSSL and zlib; and security-critical and commonly used components of the Linux kernel, including Kernel-based Virtual Machine, according to the Zalewski post.

“So we decided to try something new: provide financial incentives for down-to-earth, proactive improvements that go beyond merely fixing a known security bug,” Zalewski said. “Whether you want to switch to a more secure allocator, to add privilege separation, to clean up a bunch of sketchy calls to strcat(), or even just to enable ASLR  – we want to help!”

In the future, Google is hoping to expand the OSS bug bounty program to web servers, including Apache httpd, lighttpd and nginx; SMTP services, including Sendmail, Postfix and Exim; toolchain security improvements for GCC, binutils and llvm; and OpenVPN, Zalewski said in the post.

“We're excited about this new effort, which complements and extends our long-running vulnerability reward programs for Google web applications and for Google Chrome,” a Google spokesperson told SCMagazine.com on Thursday.

Not everyone is convinced vulnerability reward programs mitigate threats entirely. Aviram Jenik, CEO of vulnerability assessment company Beyond Security, told SCMagazine.com on Thursday that his personal experiences with Google's bug bounty program have been “not stellar.”

“Interesting thought: Anyone who sells a weaponized vulnerability to the highest bidder and does it anonymously could possibly also sell the solution to Google,” Brian Pearce, COO of Beyond Security, told SCMagazine.com on Thursday.

[An earlier version of this story incorrectly stated that Brian Pearce is COO of Beyond Trust].  

Share this article:

Sign up to our newsletters

More in News

POS malware risks millions of payment cards for Michaels, Aaron Brothers shoppers

POS malware risks millions of payment cards for ...

An investigation dating back to January has finally confirmed that malware on point-of-sale systems may have compromised payment card data for millions of Michaels Stores and Aaron Brothers customers.

Phishing scam targets Michigan public schools

Unknown attackers used the finance director's email account to request wire transfers from the school district's accounting department.

Contempt order against Lavabit still stands, appeals court rules

Contempt order against Lavabit still stands, appeals court ...

A federal appeals court backed an earlier ruling penalizing the email service.