Menu
Encrypted messaging startup Wickr offers $100K bug bounty

Encrypted messaging startup Wickr offers $100K bug bounty

The company hopes to tap the security research community to find potential problems

Two-year-old startup Wickr is offering a reward of up to US$100,000 to anyone who can find a serious vulnerability in its mobile encrypted messaging application, which is designed to thwart spying by hackers and governments.

The reward puts the small company in the same league as Google, Facebook and Microsoft, all of which offer substantial payouts to security researchers for finding dangerous bugs that could compromise their users' data.

Wickr has already closely vetted its application so the challenge could be tough. Veracode, an application security testing company, and Stroz Friedberg, a computer forensics firm, have reviewed the software, in addition to independent security researchers.

In a statement, Wickr said "we expect finding critical vulnerabilities in Wickr to be difficult and are honored to work with those that do."

Companies benefit from these bug bounty programs because they create an incentive for a large number of engineers with various types and levels of expertise to test their applications. It can be a better investment than hiring full-time staff, according to one study.

Wickr said vulnerabilities that substantially affect the confidentiality or integrity of user data could qualify for the maximum reward. Less severe bugs could garner a researcher $10,000 or more. Researchers are required not to publicize their discoveries for three months without written permission, giving Wickr time to review and fix potential issues. Bug information should be sent to bugbounty@mywickr.com.

Messages sent through Wickr are encrypted on the mobile device. Although the scrambled data passes through Wickr's servers, Wickr does not have a key to decrypt the content. A message can be tagged with an expiry date that causes it to be erased on the recipient's phone after a specific time.

Wickr, based in San Francisco, promotes its application, which runs on iOS and Android, as a safe way to send messages, photos, files and video. Since it does not retain data on its servers, the company maintains it would be unable to turn over users' data to law enforcement.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Subscribe here for up-to-date channel news

Follow Us

Join the New Zealand Reseller News newsletter!

Error: Please check your email address.

Tags securityWickrencryptionExploits / vulnerabilities

Featured

Slideshows

​Reseller News Connect – Securing your future as an MSP

​Reseller News Connect – Securing your future as an MSP

This Reseller News Connect event uncovered the threat landscape in a Kiwi context, highlighting how MSPs can securely manage IT environments, while implementing business continuity solutions to avoid unexpected disasters.

​Reseller News Connect – Securing your future as an MSP
StorageCraft celebrates high achievers at its inaugural A/NZ Partner Awards

StorageCraft celebrates high achievers at its inaugural A/NZ Partner Awards

Revealed at a glitzy bash in Sydney at the Ivy Penthouse, the first StorageCraft Partner Awards locally saw the vendor honour its top-performing partners with ASI Solutions, SMBiT Pro, Webroot, ACA Pacific and Soft Solutions New Zealand taking home the top awards. Photos by Maria Stefina.

StorageCraft celebrates high achievers at its inaugural A/NZ Partner Awards
Show Comments