Hi friends,

The other day I blogged[1] about there being a bug bounty program coordinated by Hacker One for which you can apply for if your detected curl security problems are serious enough. A few persons who reported curl bugs have already received payments. The highest paid one so far that I saw got 3,000 USD.

I think this is super awesome as I hope it can provide some extra energy to people to go in a little extra when trying to find problems in our products. Getting security problems reported (and fixed) is a good thing.

I'm now in communication with the good folks at Hacker One to see what we can do to cooperate to make it an ever better and perhaps more focused bounty program for curl issues. I'll probably get back with details on that if/when we accomplish something.

[1] = https://daniel.haxx.se/blog/2017/04/19/curl-bug-bounty/

--

 / daniel.haxx.se
-------------------------------------------------------------------
Unsubscribe: https://cool.haxx.se/list/listinfo/curl-library
Etiquette:   https://curl.haxx.se/mail/etiquette.html

Reply via email to