Skip to main content

Intel opens bug hunt to all security researchers, offers possible $250K payout

Want to make a quick $250,000? Who doesn’t, right? If you have the know-how to hunt down vulnerabilities in hardware and software, then that high-dollar reward could be within your grasp. Intel is now offering an updated bug bounty program until December 31, 2018, setting that nice little chunk of change as the maximum payout for hunting down “side-channel vulnerabilities.” These vulnerabilities are hidden flaws in typical software and hardware operations that could potentially lead hackers to sensitive data, like the recent Meltdown and Spectre exploits. 

“In support of our recent security-first pledge, we’ve made several updates to our program,” the company says. “We believe these changes will enable us to more broadly engage the security research community and provide better incentives for coordinated response and disclosure that help protect our customers and their data.” 

Intel originally launched its Bug Bounty Program in March 2017 as an invitation-only plan for select security researchers. Now the program is open to all in hopes of minimizing another Meltdown-type discovery by using a wider pool of researchers. The company is also raising the reward amounts for all other bounties, some of which offer up to $100,000. 

Intel’s list of requirements for reporting side-channel vulnerabilities is somewhat short, including the 18-year-old age requirement, a six-month gap between working with Intel and reporting an issue, among other requirements. All reports must be encrypted with the Intel PSIRT public PGP key, they must identify an original undisclosed problem, include CVSS v3 calculation results, and so on. 

Intel wants security researchers to hunt down bugs in its processors, chipsets, solid state drives, stand-alone products like NUCs, networking and communication chipsets, and field-programmable gate array integrated circuits. Intel also lists five types of firmware, and three types of software that fall under its bug bounty umbrella: drivers, applications, and tools. 

Intel will award a Bounty for the first report of a vulnerability with sufficient details to enable reproduction by Intel,” the company states. “Intel will award a Bounty from $500 to $250,000 USD depending on the nature of the vulnerability and quality & content of the report. The first external report received on an internally known vulnerability will receive a maximum of $1,500 USD Award.” 

In January, researchers went public with a vulnerability found in processors dating back to 2011 that allows hackers to access the system memory and grab sensitive data. The attack vector takes advantage of a method processors use to predict the outcome of a process string. Using this predictive technique, processors store sensitive data in the system memory in an unsecured state. 

One method of gaining access to this data is called Meltdown, which requires special software to capture the data. With Spectre, hackers could trick legitimate apps and programs into coughing up the sensitive data. Both methods are theoretical, and currently not actively exploited in the wild, yet Intel seemed somewhat embarrassed over the potential issues. 

“We will continue to evolve the program as needed to make it as effective as possible and to help us fulfill our security-first pledge,” Intel promises. 

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
Surfshark CleanWeb merges ad blocking and a VPN to stop hidden digital horrors
Surfshark CleanWeb combines a VPN and an ad-blocker for maximum privacy

While one could argue that internet browsing has never been anonymous or completely safe, there's no argument against the point that it's getting worse. Intrusive advertisements, corporate and e-commerce trackers, traffic tied to your home IP address, and phishing scams are just a few of the major headaches waiting for you when you browse. It's device-agnostic, as well. You'll be tracked and bombarded no matter what your device is, from a smartphone to a desktop computer. Worse yet, the tracking jumps between platforms in most cases, which is why you often see advertisements on social media and other websites for products you've viewed in the past. A VPN or virtual private network can help, but it won't stop everything. That is unless you use Surfshark CleanWeb, an excellent and more comprehensive online tool than free ad blockers and most comparable solutions. It blends the support of a powerful ad blocker and a VPN to give you some of the best coverage out there. Let's explore further, and we'll also discuss how you can save over 80% on one-year and two-year plans and get two months free.

 
What can Surfshark CleanWeb block?
Forget about intrusive ads and pop-ups on your devices — the Surfshark ad blocker stops them. It can also prevent annoying video ads on smart TVs, repeated cookie requests and pop-ups from your browser(s), and more. For example, once installed, Surfshark's CleanWeb 2.0 browser extension can warn you to prevent you from visiting malware-filled fake websites and protect you from hidden website data breaches.

Read more
Best iPad deals: Save on iPad Air, iPad Pro, iPad Mini
iPad Pro 2020 Screen.

For years the Apple iPad has been setting the standard for the best tablets, and despite its more premium nature, you can generally find some great iPad deals among the best tablet deals. That’s certainly the case right now, as there are a lot of iPad deals to shop. And while many of the best Apple deals include fan favorites like iPhone 15 deals, MacBook deals, and even AirPods deals, the current iPad deals have a lot to choose from. We’ve rounded up all of the best iPad deals worth shopping right now. Reading onward you’ll find discounts on everything from budget iPads to recent releases, as well as some some savings on iPad accessories.
Apple iPad 10.2 (9th Gen) 64GB Wi-Fi -- $249, was $329

Apple's A13 Bionic chip is no M1 or M2, but it still offers 64-bit architecture and neural engine support for excellent performance. In other words, this 10.2-inch iPad is incredible value. It has a 10.2-inch Retina display, 64GB of storage, supports Touch ID and Apple Pencil (1st Gen), and it's size, plus all-day battery life make it an excellent choice for anyone with an on-the-go lifestyle.

Read more
8 AI chatbots you should use instead of ChatGPT
Copilot on a laptop on a desk.

When ChatGPT launched in late 2022, it was a novelty. It didn't take long, however, for competition to come along.

Early on, there weren’t many ChatGPT alternatives available that weren’t in-house, research-based options or open source projects on GitHub that required some sort of coding knowledge to set up and operate. But since then, several companies have developed consumer products with free and paid tiers and a plethora of enterprise and developer options. So, if you aren't satisfied with ChatGPT for whatever reason, these are the eight other options to try out instead.
Microsoft Copilot

Read more