Mozilla Hikes Security Bug Bounty to $3000
Mozilla’s six-year-old Security Bug Bounty Program, which rewards security researchers for reporting bugs in its software, just became more lucrative. The bounty payment has now been hiked from $500 to $3000 per eligible bug, Mozilla announced on its blog. This has been done “to make it economically sustainable for security researchers to do the right thing when disclosing information.”
The company has made some additions and subtractions to the list of products covered under the bounty program. It has also amended the eligibility terms to better elucidate its “right to disqualify bugs from the bounty payment if the reporter has been deemed to have acted against the best interests of our users.” However, Mozilla clarified that publicly disclosed bugs will continue to be eligible for the bounty program despite the amendments.
“We have also clarified the products covered under the bounty to better reflect the threats we are focused upon. We still include Firefox and Thunderbird obviously, but we also added Firefox Mobile and any Mozilla services that those products rely upon for safe operation,” Mozilla said. “Release and beta versions of those products are eligible. Mozilla Suite bugs however is no longer eligible, as it is not an officially released nor supported Mozilla product.”

Comments
Comments are closed on this article
![]()
Five Rabbits
July 18, 2010 at 9:23am
Paying people who find and report security flaws instead of sending cops to kick down their door, denying the flaws exists and failing to fix them? What kind of crazy buisness stratgey is that? Clearly they dont have an overpaid PR department to handle things like that.
![]()
Talcum X
July 18, 2010 at 6:35am
but I dont think they will pay 3K for a dead roach!
***********
Every morning is the dawn of a new error.
"In Ireland, there are more drunks per capita than people." - Peter Griffin
Log in to MaximumPC directly or log in using Facebook
Forgot your username or password?
Click here for help.
















