I have written before about how good “bug bounties” are for improving everyone’s cyber security, rewarding the white hat hackers and researchers for their work.
The Open Source Software Vulnerability Rewards Program (OSS VRP)
Now Google has launched a bug bounty program that rewards the ethical technologists for finding and securely reporting bugs in, not only in Google open source software projects, but in other open source software as well. Google considers this a good way to help secure the various supply chains as many software products rely on open source software and software modules from various repositories – which can and have be compromised.
Google offers up to $31,337 for open-source project bugs • The Register
The top amount they are offering is odd – until you do the password trick of substituting numbers for letters…
Clive Catton MSc (Cyber Security) – by-line and other articles
Further Reading
Google Open Source Software Vulnerability Reward Program Rules – Rules – About – Google Bug Hunters