ALL >> Computers >> View Article
Facebook Alters Bug Disclosure Policy To Encourage Information Security Experts
Security has become the buzzword in the IT industry. Rising number of security breaches has been a cause for concern for organizations, software developers, websites and vendors of security products. While hackers constantly endeavor to exploit vulnerabilities, software developers have to invest considerable resources on other factors such as product innovation, research and marketing along with security. Off late, information security researchers have been discovering bugs in software products, web applications and security products to aid developers in coming up with appropriate security patches. Recently, popular social networking site, Facebook modified its bug disclosure policy to encourage information security researchers to discover vulnerabilities. The wording of the earlier policy gave an impression that information provided by security professionals may be used to take action against them. The wrong wording of the policy scared many researchers from informing vulnerabilities to Facebook. Some of the prominent vendors such as Google and Mozilla ...
... offer financial rewards to security professionals for revealing high and critical vulnerabilities.
Usually, organizations use the services of certified ethical hackers to reveal the vulnerabilities. The new disclosure policy clarifies that no legal action will be initiated against researchers for sharing vulnerabilities, if the action was done in good faith and Facebook receives reasonable time to respond. The clarification will inspire security professionals to help Facebook pre-empt hackers in discovering vulnerabilities and initiating corrective action. The popularity of Facebook has made it an easy target for hackers to uncover loads of personal information to thousands of individuals. Social networking sites such as Facebook and Twitter witness several instances of fake accounts from offenders in the name of celebrities and top officials. Therefore, security is one of the prime concerns for these sites.
Hackers can misuse the vulnerabilities on websites to inject malware, redirect to fake websites, create fake accounts, reveal username and passwords, and gain unauthorized access to associated databases. Organizations must encourage their employees to enroll in IT security courses to keep themselves updated on the latest tools and techniques. Internet users must vary of fake e-mails purportedly coming from a legitimate networking site with invitation from unknown members. The links in the e-mail may lead users to fake websites, where there information may be compromised.
Add Comment
Computers Articles
1. What Identity Governance Really Means In Modern EnterprisesAuthor: Mansoor Alam
2. Strategies For Successful Site Selection In Clinical Trials
Author: Giselle Bates
3. Simplifying Business Purchases With Smart, Reliable Procurement Solutions
Author: suma
4. How Businesses In Dubai Are Scaling Faster With Modern Erp Software
Author: Al murooj solutions
5. How To Choose The Right Weapon Tracking System: 7 Must-have Features
Author: 3PL Insights
6. Power Bi Tutorial For Beginners: Learn Business Intelligence Step By Step
Author: Tech Point
7. Spark Matrix™: Data Governance Solutions
Author: Umangp
8. How Prediction Market Software Development Is Transforming Data-driven Decision Making
Author: david
9. Naming Development & Management
Author: brainbell10
10. Mysql Database Development & Management Services
Author: brainbell10
11. Mongodb Development & Management
Author: brainbell10
12. Spark Matrix™: Conversational Automation
Author: Umangp
13. How Care Home Software Helps Improve Daily Operations In Care Homes
Author: Centrim Life UK
14. Pc & Tech Stores: Latest Trends In Hardware And Accessories
Author: Jack Williams
15. The Infozed Blueprint: Powering The Modern Workspace
Author: suma






