PayPal Starts Bug Bounty Program 39
Trailrunner7 writes "PayPal is the latest company to join the ranks of software vendors and Web properties that offer bounties to security researchers who privately disclose new bugs to them. The company isn't saying how much it will pay for each bug, just that its security team will determine the severity of each flaw as well as the ultimate payout. PayPal's decision to offer financial incentives to researchers follows the establishment of similar programs by companies including Google, Mozilla, Facebook, Barracuda and others. Google's bug bounty program may be the most well-known and comprehensive, as it includes bugs not just in its software products such as Chrome, but also its Web properties. The company has paid out more than $400,000 in rewards to researchers since the program began and researchers who consistently find bugs in Google's products can make a nice side income off the program."
Bugs? (Score:2)
People who know this and continue to use PayPal... well... wow.
Re:Bugs? (Score:5, Insightful)
Re: (Score:1)
Re:Bugs? (Score:4, Funny)
Re: (Score:3, Insightful)
Re: (Score:2)
Re: (Score:3)
"Software that has been around and has been tested thoroughly isn't going to have a lot of bugs. PayPal shouldn't have any glaring bugs at this point."
That's why they have waited until _now_ to pay for bugs.
It's financially responsible.
Re:Bugs? (Score:5, Informative)
Re: (Score:2)
I am very prowd to say, my code contains NO bugs. At all. Ever. I know, you wish you where the AWSOME me...
Re: (Score:1)
Re: (Score:2)
hahahahahahahahahaha *cough* *cough* *hack* (Score:4, Insightful)
Oh my gods.. I can't breathe!
What the hell is this? Since when has Paypal been concerned about quality of service to ANYONE?
Every problem I have ever reported has resulted in a metaphorical slap in the face, tons of paperwork, or both. Everyone is guilty until proven innocent but the scammers who can easily sidestep anything they do and only the honest get punished. Why would this be different with bugs?
Re: (Score:3)
Since when has Paypal been concerned about quality of service to ANYONE?
Only for us little people...
They gave Joe Lieberman fantastic service [guardian.co.uk].
This is Awesome (Score:2)
Re: (Score:2)
You'll be far richer if you *don't* tell Paypal about those undocumented, database leaks with direct links to your private banker in Grand Cayman. So STFU.
Re: (Score:2)
not my fault you don't get the reference...
Re: (Score:2)
Re: (Score:1)
No.. Rob Malda has just picked you for an anal sex romp. Enjoy it.
Re: (Score:2)
I FOUND A BUG!! (Score:5, Informative)
It's their Management. If they would fix that....
How much is that worth?
Re: (Score:1)
No, it's the entire almost monopoly that is the biggest bug. Eliminate that, and then you the management would go. Either by the company collapsing, or the bad management being gotten rid of.
Personally I have great hopes for BitCoin, but think that the current gateways between the payment system and the external money are too insecure to trust putting any actual money into it.
Re: (Score:2)
Re: (Score:2)
OK, let me go do that. ;)
Tricksy tricksy (Score:2)
The bounty will be paid in your paypal account (if you do not have one, you will have to create one), and then paypal will freeze your account without any explanation or appeal process :)
I found one! (Score:3)
Oh and every time I go to their site, it attempts to launch the default media player plugin for whatever browser I'm using which gets blocked as a security threat by default in default configurations of IE8 and 9 and I think Firefox as well.
Re: (Score:3)
Arguably, yes.... but to make any claim on a bounty, you are obligated to discuss the matter with them privately.
As you've already openly disclosed it here, however... it is too late for that.
Don't Worry (Score:1)
I've already got a team of Nigerians on it.
Not in the software (Score:2)
The problem is that most of the bugs are in the human end of the system, not in the software.