Skip to main content

United hackers given million free flight miles

The flight provider operates a "bug
bounty" scheme that rewards hackers for
privately disclosing security flaws rather
than sharing them online.
It has given the maximum reward of a
million flight miles, worth dozens of trips,
to two people.
One security expert said the scheme was a
big step forward for online security.
"Schemes like this reward hackers for
finding and disclosing problems in the
right way. That makes the internet safer
for all of us," said security consultant Dr
Jessica Barker.
"Bug bounties are common in tech
companies as they tend to understand
online security a bit more, but other
industries are catching up," said Dr
Barker.
Cash incentives
The idea of responsible disclosure,
reporting issues and giving companies
time to fix them, is not new.
Big technology companies such as Yahoo,
Google and Facebook offer hackers cash
incentives to report bugs privately.
In return for receiving their flight
rewards, hackers are forbidden from
revealing the nature of the security holes
they discovered.
"We believe that this program will further
bolster our security and allow us to
continue to provide excellent service,"
United said on its website.
The company declined to comment
further.
"It's not always about hackers digging
around looking for flaws. A hacker may be
using a service and notice something a bit
off," said Dr Barker.
"We all benefit if they look into that," she
added.
Some critics of bug bounties say they can
discourage companies from hiring
professional security staff, because it's
cheaper to offer hackers cash for
disclosing bugs.
Dr Barker disagrees: "It should be part of
an overall approach to security, but it's
definitely a good approach.
"It encourages positive behaviour and
shows young hackers that they can benefit
from doing the right thing.
"Bounties can also benefit smaller
companies who can't afford to give out
cash rewards but can offer free products
or services, so I hope we'll see more and
more bug bounties," she said.

Comments

Popular posts from this blog

Google Authenticator, a formidable layer of protection to your account.

​Google Authenticator is a free security app that can protect your accounts against password theft. It's easy to set up and can be used in a process called two-factor authentication (2FA) offered on popular social media services like Gmail, Facebook, Twitter, Instagram, etc.  The app ( iOS / Android ) generates a random code used to verify your identity when you're logging into various services. The code can technically be sent to your phone via text message every time— but the Google Authenticator app provides an extra level of security.  SMS-based 2FA has a  known security flaw , and any devoted hacker can attempt to  socially engineer  an attack against your phone company. The Google Authenticator app eliminates the possibility of an SMS-based attack  using algorithms  to generate the codes on your phone. Here's how to set it up: 1. Download Google Authenticator from either the Apple App Store or the Android Google Play store. It's free. 2. Nex...

Floyd Mayweather Baby Mama Sues for $20 Mil ... He's a Despicable Liar

Floyd Mayweather could lose tens of millions of dollars from his big payday if his baby mama gets her way ... because she's just filed a lawsuit claiming he ruined her with lies to save his own ass. Josie Harris, who has 3 kids with Floyd, claims he lied through his teeth in an interview with Katie Couric just 2 weeks before the big fight ... when he claimed Josie was in a drug-fueled rage and he had to "restrain" her during their infamous 2010 domestic violence incident. Point of fact ... Floyd was convicted of domestic violence and spent two months in jail. Josie recounts her terror in the lawsuit, explaining how she and Floyd had broken up ... but he flew into a jealous rage that night, broke into her home and viciously attacked her while she was sleeping on her couch ... and her kids saw part of the beating. Harris says she is now labeled a drug addict thanks to Mayweather's lies -- and was embarrassed and humiliated on a global scale.   Her lawyer, Dan Friedl...

Google, harder to search for results from other countries

For a long time, there was an easy way to conduct a Google search in a country other than the one you’re in. If you wanted to get results specific to Japan, for instance, you would visit www.google.co.jp; to get Australian results you would visit www.google.com.au — but this trick no longer works. Google has announced that it will now always serve up results that are relevant to the country that you’re in, regardless of the country code top level domain names (ccTLD) you use. The reason given is a little bizarre. The search giant says that the change has been introduced because of the way people are using the search engine these days. It says: “around one in five searches on Google is related to location, so providing locally relevant search results is an essential part of serving you the most accurate information.” The argument seems counterintuitive, however. Anyone who has changed the ccTLD has done so consciously, and for a reason — for Google to override this decision is strange...