The and-httpd server has a $2,000 "security guarantee"
1–10 of 13 posts
Re: The and-httpd server has a $2,000 "security guarantee"
#2Re: The and-httpd server has a $2,000 "security guarantee"
#3That page was last modified in 2006. It must have held up well against attacks or he would be broke by now!
Re: The and-httpd server has a $2,000 "security guarantee"
#4Re: The and-httpd server has a $2,000 "security guarantee"
#5Last update from changelog is 2006-09-10
Re: The and-httpd server has a $2,000 "security guarantee"
#6Re: The and-httpd server has a $2,000 "security guarantee"
#7Dovecot also has a similar guarantee: http://dovecot.org/security.html
As does Mozilla: http://www.mozilla.org/security/bug-bounty.html
Even Facebook is in on the game: http://www.facebook.com/whitehat/bounty/
Bug bountying in general of course started with Donald Knuth: http://en.wikipedia.org/wiki/Knuth_reward_check and has recently become moderately popular as a strategy for increasing open-source code quality: http://www.daemonology.net/blog/2011-09-05-lessons-learned-f...
Re: The and-httpd server has a $2,000 "security guarantee"
#8Here is the latest source for anyone with too much time on their hands: http://www.and.org/and-httpd/0.99.11/ Last update from changelog is 2006-09-10
Re: The and-httpd server has a $2,000 "security guarantee"
#9Re: The and-httpd server has a $2,000 "security guarantee"
#10This sort of thing is not new. I think the first one was qmail: http://cr.yp.to/qmail/guarantee.html followed shortly by djbdns: http://cr.yp.to/djbdns/guarantee.html (which was awarded in 2009: http://article.gmane.org/gmane.network.djbdns/13864 ) Dovecot also has a similar guarantee: http://dovecot.org/security.html As does Mozilla: http://www.mozilla.org/security/bug-bounty.html Even Facebook is in on the game: ht…