Home Security Million-dollar bounty offered for Tor exploits

Million-dollar bounty offered for Tor exploits

An exploit vendor has offered a bounty of US$1 million for zero-day exploits that target the Tor browser on Tails Linux and Windows.

The Washington DC-based Zerodium said the offer was open until 30 November.

However, it added a rider: the bounty could be withdrawn if its total payments to researchers reached US$ 1 million.

The million-dollar offer for Tor exploits is for those that work with JavaScript blocked. The default install of Tor allows JavaScript to run and exploits for the browser in this state will earn lower payouts

The Tor browser is used by security-conscious individuals and can be used to access those portions of the Internet known as the dark web.

zerodium million

In a Q and A, the company said it was offering the million-dollar bounty for Tor to make the world a safer place.

"While the Tor network and Tor Browser are fantastic projects that allow legitimate users to improve their privacy and security on the Internet, the Tor network and browser are, in many cases, used by ugly people to conduct activities such as drug trafficking or child abuse," the company said.

"We have launched this special bounty for Tor Browser zero-days to help our government customers fight crime and make the world a better and safer place for all." 

In a FAQ, Zerodium explained that its customers were mainly US Government agencies.

"Zerodium customers are mainly government organisations in need of specific and tailored cyber security capabilities, as well as major corporations from defence, technology, and financial sectors, in need of protective solutions to defend against zero-day attacks," it said.

"Access to Zerodium solutions and capabilities is highly restricted and is only available to a very limited number of organisations."

Last month, Zerodium offered increased bounties for exploits targeting apps used for encrypted messaging.

LEARN NBN TRICKS AND TRAPS WITH FREE NBN SURVIVAL GUIDE

Did you know: Key business communication services may not work on the NBN?

Would your office survive without a phone, fax or email?

Avoid disruption and despair for your business.

Learn the NBN tricks and traps with your FREE 10-page NBN Business Survival Guide

The NBN Business Survival Guide answers your key questions:

· When can I get NBN?
· Will my business phones work?
· Will fax & EFTPOS be affected?
· How much will NBN cost?
· When should I start preparing?

DOWNLOAD NOW!

Sam Varghese

website statistics

A professional journalist with decades of experience, Sam for nine years used DOS and then Windows, which led him to start experimenting with GNU/Linux in 1998. Since then he has written widely about the use of both free and open source software, and the people behind the code. His personal blog is titled Irregular Expression.