>> (p.1)
    Author Topic: Vulnerability bounties proposal  (Read 2350 times)
    Sergio_Demian_Lerner (OP)
    Hero Member
    *****
    expert
    Offline Offline

    Activity: 555
    Merit: 662


    View Profile WWW
    May 06, 2012, 02:10:17 PM
     #1

    I´ve dedicated some time to research Bitcoin security and resiliency and I´m investigating some possible attacks and corresponding patches. The problem is that I cannot use more of my work time for the project, since I must earn my living. Since I really would like to go forward with this research, It would be great if the community (the developers, the exchanges, all of us) could donate bitcoins to create vulnerability bounties. This would give an incentive for researchers like me to leave out other tasks and focus on Bitcoin. Also bounties would reduce the risk that vulnerabilities are sold in black markets.

    For example, we could give bounties (sorted by severity) for:

    1. Remote code execution
    2. Stealing money by exploiting bugs using specialty crafted transactions/blocks.
    3. Low cost Denial of Service of the whole Bitcoin network
    4. Lost of privacy pseudo-anonymity.

    In the first 3 cases people should immediately download a new client version to allow the network to keep running.

    I think we won´t find many vulnerabilities of type 1-2 but we might find many vulnerabilities of type 3-4. A vulnerability of type 3 may render Bitcoin out of reach for days, and this would cost exchangers (and most of us) a lot of money.

    What do you think?

    Best regards,
     Sergio.
Page 1
Viewing Page: 1