Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

2/14/2018
04:35 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Intel Expands Bug Bounty Program, Offers up to $250K

Microprocessor giant adds vulnerability-finding category for Meltdown, Spectre-type flaws.

Intel is doubling down on its existing bug bounty program by opening it up to all security researchers and adding an entire category for vulnerabilities akin to the dangerous Meltdown and Spectre flaws recently exposed in its microprocessors.

The chip company today announced that it had expanded its nearly one-year old bug bounty program in an effort to forge closer ties to the security research community and offer bigger financial incentives for coordinated response and disclosure of flaws in its products.

Intel previously ran an invitation-only bug bounty program. In addition to opening up its vulnerability compensation program to all researchers, Intel also added a section specifically for side-channel vulnerabilities through Dec. 31 of this year. Researchers who discover these types of bugs can earn up to $250,000, the company said.

"In support of our recent security-first pledge, we’ve made several updates to our program. We believe these changes will enable us to more broadly engage the security research community, and provide better incentives for coordinated response and disclosure that help protect our customers and their data," Rick Echevarria, vice president and general manager of platform security at Intel wrote in a post announcing the changes.

Intel also raised bug bounty award amounts overall, with grants up to $100,000. The company's program runs on HackerOne's platform

These changes to the program come in the wake of the major disclosure last month of critical flaws in most modern microprocessors, including Intel's: a common method used for performance optimization could allow an attacker to read sensitive system memory, which could contain passwords, encryption keys, and emails, for example.

The so-called Meltdown and Spectre hardware vulnerabilities allow for so-called side-channel attacks. With Meltdown, sensitive information in the kernel memory is at risk of being accessed nefariously; with Spectre, a user application could read the kernel memory as well as that of another application. The end result: an attacker could read sensitive system memory containing passwords, encryption keys, and emails — and use that information to help craft a local attack.

Intel's new bug bounty program for side-channel vulns focuses on vulnerabilities in hardware that are exploitable in software, the company said. "Through this special program, Intel hopes to accelerate new innovative research and learning around these types of security issues," Intel said in a post detailing the short-term bounty.

The bug bounties for the side-channel flaws range from up to $5,000 for low-severity flaws to $250,000 for critical flaws.

"Like many large, complex organizations, Intel is searching for the right incentive model to help protect their users and supply chain partners. It isn't as simple as throwing more money at a problem to really secure the Intel ecosystem," says Katie Moussouris, founder of Luta Security. "Careful reward structures that are lawful for the company, the participating hackers, the partners, and the customers take a considerable amount more to develop, so I hope for all of society's sake that chip manufacturers and other members of the global critical computing infrastructure evolve thoughtfully to bounty smarter, not harder."

Intel has been under fire for the fallout experienced by the initial firmware fixes it released for Meltdown and Spectre. The company issued an unusual advisory late last month  urging its customers and partners to refrain from applying some of the firmware patches. Navin Shenoy, executive vice president and general manager of Intel's Data Center, called for customers and OEMs to halt installation of patches for its Broadwell and Haswell microprocessors after widespread reports of spontaneous rebooting of systems affixed with the new patches.

Meanwhile, Intel CEO Brian Krzanich told analysts in an earnings call late last month that the company will roll out new products later this year that mitigate the Meltdown and Spectre vulnerabilities.

Alex Rice, co-founder and CTO of HackerOne, says Intel's short-term bounty for side-channel vulnerabilities makes sense. "Bounty programs are more powerful the more they incentivize the specific type of research that would be most valuable to the company," he says. "In Intel's case, side-channel attacks are a highly complex specialization that their team has invested heavily in defending against."

Related Content:

 

 

 

Black Hat Asia returns to Singapore with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier solutions and service providers in the Business Hall. Click for information on the conference and to register.

Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
AI Is Everywhere, but Don't Ignore the Basics
Howie Xu, Vice President of AI and Machine Learning at Zscaler,  9/10/2019
Fed Kaspersky Ban Made Permanent by New Rules
Dark Reading Staff 9/11/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-14540
PUBLISHED: 2019-09-15
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.
CVE-2019-16332
PUBLISHED: 2019-09-15
In the api-bearer-auth plugin before 20190907 for WordPress, the server parameter is not correctly filtered in the swagger-config.yaml.php file, and it is possible to inject JavaScript code, aka XSS.
CVE-2019-16333
PUBLISHED: 2019-09-15
GetSimple CMS v3.3.15 has Persistent Cross-Site Scripting (XSS) in admin/theme-edit.php.
CVE-2019-16334
PUBLISHED: 2019-09-15
In Bludit v3.9.2, there is a persistent XSS vulnerability in the Categories -> Add New Category -> Name field. NOTE: this may overlap CVE-2017-16636.
CVE-2019-16335
PUBLISHED: 2019-09-15
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.