
Five holes plugged
By Dan Ilett
Published: 31 March 2005 15:15 GMT
The Mozilla Foundation has given $2,500 to a security researcher for discovering vulnerabilities in its free web browser.
The company paid $500 to German researcher Michael Krax for each of the five bugs he found in Firefox.
"We developed the bug bounty programme to encourage and award community members who identify unknown bugs in the software," said Chris Hofmann, director of engineering for the Mozilla Foundation. "This programme is one of the many ways the Mozilla Foundation produces safe and secure software for its users."
The National Infrastructure Coordination Centre earlier this month posted alerts about the bugs, which relate to chrome privileges — a mechanism that allows applications to change user interface details of the browser itself. If abused, this function could alter the 'Home' button, for example, to make it download malicious programs.
Mozilla is one of the few organisations to offer financial incentives to people who find vulnerabilities. Microsoft, which charges for its products and regularly asks the user community to test beta versions of its software, has no such scheme.
A spokesperson for Microsoft said: "We don't pay people to find bugs but there are other ways we try to fix security as much as possible. But we can't comment on what Mozilla does."
Microsoft also highlighted its cash-reward scheme for informants who help law enforcement agencies to convict virus writers.
Dan Illet writes for ZDNet UK
LOL, yeah microsoft pays people to tell on virus w...
poetfreak
M$ sound a little tongue tied. Imagine they offeri...
Anonymous
Microsoft don't pay people for information on bugs...
Anonymous
I feel the need to ask about Apple here, i guess t...
Anonymous
Apple only has to worry about monkeys as per one o...
james liddell
Major Responsibilities - Working in close coordination with the regional sales teams, VP of Global Alliances, Director of Product Marketing and the ...
The successful candidate should be MCSE qualified and the ITIL Foundation certificate is desirable. Systems Support Analyst is urgently required to ...
Documenting bugs and liaising with our Development team to fix and re-test. Some 70% of UK Local Government organisations use NDL solutions, as do ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business
Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business