Facebook rewards security spotters with debit cards
Tuesday, January 3rd, 2012Facebook is encouraging researchers to report security bugs on its site by rewarding them with debit cards.
The card, a customised Visa debit card, works in the same way as a credit card. Facebook adds more money to each researcher’s account as they report more bugs.
Ryan McGeehgan, manager of Facebook’s security response team, said in a recent interview: “Researchers who find bugs and security improvements are rare, and we value them and have to find ways to reward them. Having this exclusive black card is another way to recognize them. They can show up at a conference and show this card and say ‘I did special work for Facebook’.”
The card might also give researchers other benefits, such as passes to get into Facebook parties.
The social media giant is also planning to tap further into researchers’ knowledge. For example, researchers may be brought into products as soon as they reach production stage in order to help Facebook catch any problems as early as possible.
Researchers who report security bugs that are eventually confirmed can make at least $500, but they have to follow Facebook’s Responsible Disclosure Policy and not go public with the vulnerability information until the problem has been fixed.

