Skip to main content
  1. Home
  2. Computing
  3. News

Intel opens bug hunt to all security researchers, offers possible $250K payout

Add as a preferred source on Google

Want to make a quick $250,000? Who doesn’t, right? If you have the know-how to hunt down vulnerabilities in hardware and software, then that high-dollar reward could be within your grasp. Intel is now offering an updated bug bounty program until December 31, 2018, setting that nice little chunk of change as the maximum payout for hunting down “side-channel vulnerabilities.” These vulnerabilities are hidden flaws in typical software and hardware operations that could potentially lead hackers to sensitive data, like the recent Meltdown and Spectre exploits. 

“In support of our recent security-first pledge, we’ve made several updates to our program,” the company says. “We believe these changes will enable us to more broadly engage the security research community and provide better incentives for coordinated response and disclosure that help protect our customers and their data.” 

Recommended Videos

Intel originally launched its Bug Bounty Program in March 2017 as an invitation-only plan for select security researchers. Now the program is open to all in hopes of minimizing another Meltdown-type discovery by using a wider pool of researchers. The company is also raising the reward amounts for all other bounties, some of which offer up to $100,000. 

Intel’s list of requirements for reporting side-channel vulnerabilities is somewhat short, including the 18-year-old age requirement, a six-month gap between working with Intel and reporting an issue, among other requirements. All reports must be encrypted with the Intel PSIRT public PGP key, they must identify an original undisclosed problem, include CVSS v3 calculation results, and so on. 

Intel wants security researchers to hunt down bugs in its processors, chipsets, solid state drives, stand-alone products like NUCs, networking and communication chipsets, and field-programmable gate array integrated circuits. Intel also lists five types of firmware, and three types of software that fall under its bug bounty umbrella: drivers, applications, and tools. 

Intel will award a Bounty for the first report of a vulnerability with sufficient details to enable reproduction by Intel,” the company states. “Intel will award a Bounty from $500 to $250,000 USD depending on the nature of the vulnerability and quality & content of the report. The first external report received on an internally known vulnerability will receive a maximum of $1,500 USD Award.” 

In January, researchers went public with a vulnerability found in processors dating back to 2011 that allows hackers to access the system memory and grab sensitive data. The attack vector takes advantage of a method processors use to predict the outcome of a process string. Using this predictive technique, processors store sensitive data in the system memory in an unsecured state. 

One method of gaining access to this data is called Meltdown, which requires special software to capture the data. With Spectre, hackers could trick legitimate apps and programs into coughing up the sensitive data. Both methods are theoretical, and currently not actively exploited in the wild, yet Intel seemed somewhat embarrassed over the potential issues. 

“We will continue to evolve the program as needed to make it as effective as possible and to help us fulfill our security-first pledge,” Intel promises. 

Kevin Parrish
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
MIT researchers found a new Spectre attack that can slip past Intel and AMD defenses
AMD Ryzen CPU inside a socket installed on a motherboard

Spectre has been haunting CPU security since 2018, and MIT researchers have now found another way to make it misbehave. The new TONTOU attack can bypass some of the defenses Intel and AMD have added over the years by exploiting a tiny gap in how those protections work. The research comes from Daniël Trujillo and Mengjia Yan at MIT's Computer Science and Artificial Intelligence Laboratory (CSAIL). Their findings show that even after a processor wipes or isolates information used by its branch predictor, there can be a brief window before that information is actually used. TONTOU, short for Time-of-Neutralization to Time-of-Use, attacks precisely that gap.

The tiny gap that TONTOU exploits

Read more
Microsoft accidentally gave Windows 11 users another OneDrive app, and you can’t easily remove it
Microsoft says the wider-than-intended rollout was an accident, but removing the app currently means removing OneDrive too.
Microsoft OneDrive Featured Graphic

Windows 11 users have been getting a new OneDrive app whether they asked for it or not. The problem? Microsoft says it wasn't supposed to happen. Microsoft has confirmed that its OneDrive Photos app was rolled out to Windows 11 PCs more broadly than intended, including enterprise machines where the app isn't even designed to work. The company says it is now working on a fix, but there's an awkward catch: users currently can't uninstall OneDrive Photos without removing the main OneDrive app too.

So, what exactly got installed?

Read more
Apple Reminders sucked for project management until I learned this feature
Your checklist deserves better. Here's how to turn Reminders into a proper Kanban board.
Apple reminders on Mac

For the longest time, I used Apple Reminders only for capturing quick tasks. Thanks to its Siri integration, Reminders let me add tasks quickly so nothing would fall through the cracks. However, when it came to managing big projects, I always moved to a more powerful task manager like OmniFocus or Things 3. 

That changed the day I stumbled onto the Column view. Apple added this feature with the iOS 17 and macOS Sonoma updates, and somehow I completely missed it. But once I discovered and got the hang of it, Reminders finally started to feel like a real project management tool instead of a glorified sticky note.

Read more