Live data from Hacker News

The and-httpd server has a $2,000 "security guarantee"

and.org

1–10 of 13 posts

Re: The and-httpd server has a $2,000 "security guarantee"

#7
This sort of thing is not new. I think the first one was qmail: http://cr.yp.to/qmail/guarantee.html followed shortly by djbdns: http://cr.yp.to/djbdns/guarantee.html (which was awarded in 2009: http://article.gmane.org/gmane.network.djbdns/13864)

Dovecot also has a similar guarantee: http://dovecot.org/security.html

As does Mozilla: http://www.mozilla.org/security/bug-bounty.html

Even Facebook is in on the game: http://www.facebook.com/whitehat/bounty/

Bug bountying in general of course started with Donald Knuth: http://en.wikipedia.org/wiki/Knuth_reward_check and has recently become moderately popular as a strategy for increasing open-source code quality: http://www.daemonology.net/blog/2011-09-05-lessons-learned-f...

Re: The and-httpd server has a $2,000 "security guarantee"

#10
post #7

This sort of thing is not new. I think the first one was qmail: http://cr.yp.to/qmail/guarantee.html followed shortly by djbdns: http://cr.yp.to/djbdns/guarantee.html (which was awarded in 2009: http://article.gmane.org/gmane.network.djbdns/13864 ) Dovecot also has a similar guarantee: http://dovecot.org/security.html As does Mozilla: http://www.mozilla.org/security/bug-bounty.html Even Facebook is in on the game: ht…

And Chromium: http://www.chromium.org/Home/chromium-security/vulnerability...
Post reply on HN