Intel Expands Bug Bounty Program, Offers up to $250K

  /     /     /  
Publicated : 22/11/2024   Category : security


Intel Expands Bug Bounty Program, Offers up to $250K


Microprocessor giant adds vulnerability-finding category for Meltdown, Spectre-type flaws.



Intel is doubling down on its existing bug bounty program by opening it up to all security researchers and adding an entire category for vulnerabilities akin to the dangerous Meltdown and Spectre flaws recently exposed in its microprocessors.
The chip company today announced that it had expanded its nearly one-year old bug bounty program in an effort to forge closer ties to the security research community and offer bigger financial incentives for coordinated response and disclosure of flaws in its products.
Intel previously ran an invitation-only bug bounty program. In addition to opening up its vulnerability compensation program to all researchers, Intel also added a section specifically for side-channel vulnerabilities through Dec. 31 of this year. Researchers who discover these types of bugs can earn up to $250,000, the company said.
In support of our recent 
security-first pledge
, we’ve made several updates to our program. We believe these changes will enable us to more broadly engage the security research community, and provide better incentives for coordinated response and disclosure that help protect our customers and their data, Rick Echevarria, vice president and general manager of platform security at Intel wrote
in a post
announcing the changes.
Intel also raised bug bounty award amounts overall, with grants up to $100,000. The companys program
runs on HackerOnes platform

These changes to the program come in the wake of the major disclosure last month of critical flaws in most modern microprocessors, including Intels: a common method used for performance optimization could allow an attacker to read sensitive system memory, which could contain passwords, encryption keys, and emails, for example.
The so-called Meltdown and Spectre hardware vulnerabilities allow for so-called side-channel attacks. With Meltdown, sensitive information in the kernel memory is at risk of being accessed nefariously; with Spectre, a user application could read the kernel memory as well as that of another application. The end result: an attacker could read sensitive system memory containing passwords, encryption keys, and emails — and use that information to help craft a local attack.
Intels new bug bounty program for side-channel vulns focuses on vulnerabilities in hardware that are exploitable in software, the company said. Through this special program, Intel hopes to accelerate new innovative research and learning around these types of security issues, Intel said in a post detailing the short-term bounty.
The bug bounties for the side-channel flaws range from up to $5,000 for low-severity flaws to $250,000 for critical flaws.
Like many large, complex organizations, Intel is searching for the right incentive model to help protect their users and supply chain partners. It isnt as simple as throwing more money at a problem to really secure the Intel ecosystem, says Katie Moussouris, founder of Luta Security. Careful reward structures that are lawful for the company, the participating hackers, the partners, and the customers take a considerable amount more to develop, so I hope for all of societys sake that chip manufacturers and other members of the global critical computing infrastructure evolve thoughtfully to bounty smarter, not harder.
Intel has been under fire for the fallout experienced by the initial firmware fixes it released for Meltdown and Spectre. The company
issued an unusual advisory
late last month  urging its customers and partners to refrain from applying some of the firmware patches. Navin Shenoy, executive vice president and general manager of Intels Data Center, called for customers and OEMs to halt installation of patches for its Broadwell and Haswell microprocessors after widespread reports of spontaneous rebooting of systems affixed with the new patches.
Meanwhile, Intel CEO Brian Krzanich told analysts in an earnings call late last month that the company will roll out new products later this year that mitigate the Meltdown and Spectre vulnerabilities.
Alex Rice, co-founder and CTO of HackerOne, says Intels short-term bounty for side-channel vulnerabilities makes sense. Bounty programs are more powerful the more they incentivize the specific type of research that would be most valuable to the company, he says. In Intels case, side-channel attacks are a highly complex specialization that their team has invested heavily in defending against.
Related Content:
Intel CEO: New Products that Tackle Meltdown, Spectre Threats Coming this Year
Meltdown & Spectre: Computings Unsafe at Any Speed Problem
Fallout from Rushed Patching for Meltdown, Spectre
A Bug Bounty Reality-Check
 
 
 
Black Hat Asia returns to Singapore with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier solutions and service providers in the Business Hall. Click for information on the
conference
 and
to register.

Last News

▸ CryptoWall is more widespread but less lucrative than CryptoLocker. ◂
Discovered: 23/12/2024
Category: security

▸ Feds probe cyber breaches at JPMorgan, other banks. ◂
Discovered: 23/12/2024
Category: security

▸ Security Problem Growing for Dairy Queen, UPS & Retailers, Back off ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Intel Expands Bug Bounty Program, Offers up to $250K