Github raises bug bounty prize
New rewards and legal protections now available to researchers searching GitHub for bugs
GitHub is making things easier for researchers looking for bugs on its code-hosting site by removing the cap on its bug bounty program's top payout and offering new legal protections for white hat hackers.
After five years, the Microsoft-owned company has decided to revamp its bug bounty program by providing higher rewards for serious bugs and opening up more of its products to bug hunters.
GitHub has removed the limit on the maximum amount it will pay researchers for discovering critical bugs and they can now expect to be rewarded between $20,000 and $30,000 for each critical bug.
- EU to fund bug bounty program for top open-source software
- Google makes Chrome bug detection tool open-source
- HP launches bug bounty program for printers
The company's bug bounty rewards have also been raised at lower levels and high-severity bugs will earn researchers between $10,000 and $20,000, medium-severity rewards will earn them between $4,000 and $10,000 and low-severity rewards are now between $617 to $2,000.
Legal protections
GitHub is also removing some of the legal risks researchers participating in its bug bounty program have been exposed to for violating the site's terms. The company has added a new set of Legal Safe Harbor terms to its site policy.
Researchers will now be protected from violating the terms of the company's site if their actions are carried out specifically for bug bounty research. They will also now be exempt from GitHub's Enterprise Agreement restrictions on reverse engineering and the company vows not to sue them should they overstep the scope of the bug bounty program.
Additionally, all of GitHub's first-party services including GitHub Education, GitHub Leaning Lab, GitHub Jobs and the GitHub Desktop application will be open to researchers searching for bugs.
Are you a pro? Subscribe to our newsletter
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
The company's Phil Turnbull explained why it decided to raise its bug bounty rewards in a blog post, saying:
“We regularly assess our reward amounts against our industry peers. We also recognize that finding higher-severity vulnerabilities in GitHub’s products is becoming increasingly difficult for researchers and they should be rewarded for their efforts. That’s why we’ve increased our reward amounts at all levels.”
Via ZDNet
- Protect your devices from the latest cyber threats with the best antivirus
After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home.