GSA adds login.gov to its ongoing bug bounty program

FedScoop: The General Services Administration’s Technology Transformation Service is asking friendly hackers to test the security of login.gov, the agency’s single sign-on platform for government.

The GSA bug bounty program, the first for a civilian agency, began in August last year as part of a broader effort to draw upon outside expertise to increase the security of a variety of services. Commercial bug bounty platform HackerOne, which has handled similar projects for the military, is managing the effort. At first all of the focus was on the 18F-built Federalist website publishing service, but TTS has opened up additional domains as “targets” over the intervening months.

Read article