Mozilla Offers $10,000 Bounty For Bugs In New SSL Certificate Library

Mozilla is offering up to $10,000 to anyone capable of exposing bugs in its new SSL certificate validation library.

The non-profit organisation has invited the community to test the ‘mozilla::pkix’ library, which replaces some of the Network Security Services (NSS) features and should  improve the security of encrypted communications across its product range.

The new library will be integrated into the latest release of Firefox browser, expected in June

The announcement follows the discovery of ‘Heartbleed’ vulnerability in the open source OpenSSL protocol earlier this month.

Hearbleed was present in OpenSSL from March 2012, allowing attackers to obtain the encryption keys used by a website, decrypt any past and future traffic to the protected services and to impersonate those services at will. It was estimated at the time of the discovery that the vulnerability affected the security of as many as two-thirds of websites, including those of social networks and banks.

Leaner certificate library

The mozilla::pkix library combines several existing technologies with some new features to optimise the way an application can establish whether an encryption certificate is valid.

Encrypt“The new code is more robust because certificate path building attempts all potential trust chains for a certificate before giving up (acknowledging the fact that the certificate space is a cyclic directed graph and not a forest). The new implementation is also more maintainable, with only 4,167 lines of C++ code compared to the previous 81,865 lines of code which had been auto-translated from Java to C,” explained Camilo Viecco, systems engineer at Indiana University by day, and a bug hunter at Mozilla by night.

The new library will make its debut in Firefox 31. Mozilla had already added Transport Layer Security (TLS) 1.2 protocol support in Firefox 27.

The organisation says mozilla::pkix is fully backwards compatible, and every network security protocol currently supported by Firefox will continue to be supported. Mozilla warns that in rare cases, some website certificates will no longer validate with Firefox 31, and says such incidents should be reported.

In order to guarantee the performance of the new library, Mozilla is offering up to $10,000 to security professionals able to find vulnerabilities in mozilla::pkix code. This ‘call to arms’ is not limited to bug-hunters – Mozilla has also invited website developers to help run the new library through its paces before it hits production stages.

Are you a Firefox enthusiast? Take our quiz!

Max Smolaks

Max 'Beast from the East' Smolaks covers open source, public sector, startups and technology of the future at TechWeekEurope. If you find him looking lost on the streets of London, feed him coffee and sugar.

Recent Posts

Napster Sold And Will Return As Interactive Streaming Service

New chapter for famous name from Internet's early days, Napster, has been acquired and will…

9 hours ago

UK Proposes To Allow Satellites To Resolve UK Mobile Not-Spots

Solving not-spots? Ofcom proposal to make UK the first European country to allow ordinary smartphones…

10 hours ago

Waymo Confirms Washington DC Robotaxi Plan For 2026

Pioneering robotaxi service from Alphabet's Waymo to go live in Washington DC next year, as…

11 hours ago

US Adds 50 Chinese Firms To AI, Chip Blacklist

Dozens of Chinese firms added to US export blacklist, in order to hamper Beijing's AI…

13 hours ago

Tesla Europe Sales Plummet, As Owners Return EVs At Record Levels

Chinese rival BYD overtakes global revenues of Elon Musk's Tesla, as record number of Tesla…

15 hours ago

Signal App In Spotlight Amid Secret Chat Controversy Of US Officials

Messaging app Signal in the headlines after a journalist was invited to a top secret…

17 hours ago