Here's What Government Gets Wrong About Bug Bounties

NextGov: Bug bounties are hot in government right now, but the craze may be outpacing the contests’ actual usefulness, bug bounty practitioners tell Nextgov.

The Defense Department has launched four of the ethical hacking contests, which were first popularized at major tech firms and offer cash rewards in exchange for spotting and disclosing dangerous computer vulnerabilities.

Those contests—one each at the Pentagon and Army and two at the Air Force—netted more than 500 valid bug reports and more than $400,000 in payouts to hacker participants. Another contest, announced Monday, will challenge hackers to find vulnerabilities in the Pentagon’s travel booking system, which processes more than 25,000 transactions each day.

Read article

Share