Categories: SecurityWorkspace

Security Research Must Have Its Just Rewards

Security research should not be a thankless task; it should be a task that is celebrated, rewarded and, more importantly, acted on with all the necessary expediency that a given piece of research might deserve.

A number of events occurred this week that show how different groups value and act on security research at very different rates. On the browser front, Microsoft continues to be pummeled with an Internet Explorer (IE) zero-day flaw that is now being actively exploited. That’s two weeks after Microsoft first learned about the issue and — still — no patch.

Firefox puts Microsoft to shame

Microsoft revealed that as part of its October Patch Tuesday update set to be available on Tuesday 8 October, the flaw known as CVE-2013-3893 would be patched. Sure, Microsoft had a “Fix-It” temporary fix available for IE, but the reality is that many users don’t know about updates until they are made available on Patch Tuesday via the Windows Update system. Tens of millions of IE users have potentially been at risk for two weeks, and in my view that’s just a totally unacceptable situation.

In contrast, Mozilla, the vendor behind the open-source Firefox Web browser, this week revealed that it too was at risk from a security vulnerability. Mozilla’s director of security assurance, Michael Coats (whom eWEEK caught up with for a video interview recently), noted in a blog post that on 24 September, Mozilla was notified of a security vulnerability in its Persona authentication system. That security notification came in by way of Mozilla’s bug bounty program that rewards researchers for responsibly disclosing security research information.

Within seven days of the disclosure (and without an attack in the wild), Mozilla developers issued an update that fixed the issue.

That’s seven days, not 14, and it came with a reward for the research too.

Mozilla’s rewards to security researchers are not just a handshake and a slap on the back. Mozilla pays cash. It’s something that Yahoo is now set to do as well.

You see until this point, Yahoo has been recognising those who help out with security research by sending them a T-shirt.

“Out with T-shirts that I buy,” Ramses Martinez, director at Yahoo, wrote in a tumblr post this week. “We will now reward individuals and firms that identify what we classify as new, unique and/or high risk issues between $150 – $15,000. The amount will be determined by a clear system based on a set of defined elements that capture the severity of the issue.”

T-shirts are all fine and nice, but cash is better..  and actually fixing flaws quickly to secure users is even better!

Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

Do you know all about IT and the law? Take our quiz.

Originally published on eWeek.

Sean Michael Kerner

Sean Michael Kerner is a senior editor at eWeek and contributor to TechWeek

Recent Posts

X’s Community Notes Fails To Stem US Election Misinformation – Report

Hate speech non-profit that defeated Elon Musk's lawsuit, warns X's Community Notes is failing to…

1 day ago

Google Fined More Than World’s GDP By Russia

Good luck. Russia demands Google pay a fine worth more than the world's total GDP,…

1 day ago

Spotify, Paramount Sign Up To Use Google Cloud ARM Chips

Google Cloud signs up Spotify, Paramount Global as early customers of its first ARM-based cloud…

2 days ago

Meta Warns Of Accelerating AI Infrastructure Costs

Facebook parent Meta warns of 'significant acceleration' in expenditures on AI infrastructure as revenue, profits…

2 days ago

AI Helps Boost Microsoft Cloud Revenues By 33 Percent

Microsoft says Azure cloud revenues up 33 percent for September quarter as capital expenditures surge…

2 days ago