More Cash For Internet Bug Bounty
Written by Alex Armstrong   
Tuesday, 25 July 2017

The Internet Bug Bounty, a program that exists to make the internet safer by catching more vulnerabilities in internet infrastructure and open source software has received $300,000 in new funding.




We reported on the Internet Bug Bounty (IBB) scheme when it was launched in 2013 by Microsoft and Facebook and hosted by HackerOne. While HackerOne still supports it, IBB now has its own website and GitHub and the Ford Foundation have now joined as sponsors of the scheme, each donating $100,000. Facebook has renewed its sponsorship with another $100,000.




The rationale for running the program, as explained in the IBB's FAQs, is: 

Our collective safety is only possible when public security research is allowed to flourish. Some of the most critical vulnerabilities in the internet's history have been resolved thanks to efforts of researchers fueled entirely by curiosity and altruism. We owe these individuals an enormous debt and believe it is our duty to do everything in our power to cultivate a safe, rewarding environment for past, present, and future researchers.

Among other salient facts about IBB are: 

  • The Internet Bug Bounty has rewarded 617K+ in bounties to 142 friendly hackers for uncovering 631 flaws that have helped improve the security of the Internet including: 
    ImageTragick ($7.5k), Heartbleed and Shellshock($20k). 
  • the program is administered by an independent panel of security experts from the community, which is responsible for defining the rules of the program and allocating bounties to where additional security research is needed most

  • 100% of the funding raised from sponsors goes to finders 

Announcing GitHub's donation, Shawn Davenport

explains that the new funding will be used to expand the scope of the IBB in two ways: a new Data Processing Program to:

"encompass numerous widespread data parsing libraries as these have been an increasing avenue for exploitation"

and an expansion of;

"coverage of technologies that serve as the technical foundation of a free and open Internet, such as OpenSSL."

One of the most high profile payouts by IBB was a $15,000 bounty  for the discovery of the Heartbleed flaw in 2014. It was made to Google Security Researcher Neel Mehta, who in turn donated his award to the Freedom of Press Foundation. Such generosity isn't unusual and, according to Shawn Davenport, $45,000 of hackers' bounties from IBB have been donated to organizations like the Electronic Frontier Foundation, Hackers for Charity, and Freedom of the Press Foundation. 




More Information

Internet Bug Bounty


Related Articles

Microsoft and Facebook Launch Internet Bug Bounty Scheme

New Android Bug Bounty Scheme

Mozilla Increases Bug Bounty

Microsoft Bug Bounty Extends Scope


To be informed about new articles on I Programmer, sign up for our weekly newsletter, subscribe to the RSS feed and follow us on Twitter, Facebook or Linkedin.



Microsoft Windows Announced 40 Years Ago

Although it didn't launch until 1985, Microsoft Windows was announced in November 1983. It signaled the move for users from the command line to a GUI environment, something that some programmers still [ ... ]

Advent Of Code 2023 Unlocked

December 1st is the day on which, each year, Eric Wastl opens a very special advent calendar. You don't get rewarded with chocolates in the Advent of Code - instead it's stars for solving coding puzzl [ ... ]

More News




or email your comment to:

Last Updated ( Thursday, 14 September 2017 )