Kubernetes gets a bug bounty program

Subscribers:
4,200
Published on ● Video Link: https://www.youtube.com/watch?v=toZgNtGer5U



Duration: 2:12
8 views
0


Reported today on TechCrunch

For the full article visit: https://techcrunch.com/2020/01/14/kubernetes-gets-a-bug-bounty-program/

Kubernetes gets a bug bounty program

The Cloud Native Computing Foundation (CNCF) today announced its first bug bounty program for Kubernetes, the ubiquitous container orchestration system originally built by Google. To run this program, the CNCF is partnering with Google and HackerOne and bounties will range from $100 to $10,000.

Kubernetes already has a Product Security Committee that includes engineers from Google's own Kubernetes security team, and there are obviously plenty of eyes on the code. A bounty program, however, will get more (and new) security researchers to examine the code and help reward those who are already doing this work.

"Kubernetes already has a robust security team and response process, further cemented by the recent Kubernetes security audit," said Maya Kaczorowski the product manager for container security at Google. "We have a stronger and more secure open-source project than we've ever had before. By launching a bug bounty program, we're putting our money where our mouth is - and most importantly, rewarding the researchers already doing this important work. We hope to attract additional security researchers to get more eyes on the code, shakeout security bugs and back up our work on Kubernetes security with financial support."

The bounty includes all of the core Kubernetes components in its GitHub repository. Specifically, the team notes, it is interested in authentication bugs, potential privilege escalations and remote code execution bugs in the kubelet and API server. The CNCF also stresses that researchers are encouraged to look at the overall Kubernetes supply chain. You can find the exact details of how the program and rewards are structured here.

How Kubernetes came to rule the world




Other Videos By Colin Boyd SEO


2020-01-15Logitech Ergo K860 changed how I feel about ergonomic keyboards - CNET
2020-01-15What Do High-Performance E-Commerce Websites Do Differently? Results from the 2020 KPI Study
2020-01-15Logitech’s new split Ergo K860 keyboard expands its ergonomic accessory lineup
2020-01-15This global power adapter makes traveling with USB-C devices less of a pain
2020-01-14Announcing the agenda for Robotics+AI — March 3 at UC Berkeley
2020-01-14Ubiquity6 launches a studio editor built for the real world
2020-01-14Instagram tests Direct Messaging on web where encryption fails
2020-01-14Microsoft and NSA say a security bug affects millions of Windows 10 computers
2020-01-14A look inside Visa’s shareholder presentation for the $5.3B Plaid deal
2020-01-14Daily Crunch: Visa makes a $5.3 billion acquisition
2020-01-14Kubernetes gets a bug bounty program
2020-01-14Is Instacart’s wider rollout of Pickup an attempt to rely less on gig workers?
2020-01-14Tesla is now selling a t-shirt commemorating Cybertruck shattered window flub
2020-01-14Amazon to invest $1 billion to digitize small businesses in India
2020-01-14Reading Ted Chiang’s ‘The Merchant and the Alchemist’s Gate’
2020-01-14Four years after being acquired, Hipmunk is shutting down
2020-01-14GaN chargers are still worth getting excited about
2020-01-14Hipmunk’s co-founders tried to buy it back before the shutdown
2020-01-14Paper-rich startup employees look for ‘pre-wealth’ help to lock down stock options
2020-01-14Delta Air Lines’ startup partnerships are fueling innovation
2020-01-14Rocket Lab to open a new combined HQ, mission control and production facility in Long Beach