Secretary of Defense Ash Carter arrives at the 2016 RSA Conference in San Francisco, March 2, 2016.

Secretary of Defense Ash Carter arrives at the 2016 RSA Conference in San Francisco, March 2, 2016. DoD photo by Navy Petty Officer 1st Class Tim D. Godbee

Pentagon Launches First-of-Its-Kind Bug Bounty Program

The idea is to find and fix vulnerabilities before the bad guys do. Certain restrictions apply.

Challenged by hackers and staffing shortages, the Pentagon is inviting plainclothes techies to a competition where they can poke around military code for security bugs. The idea is to find and fix vulnerabilities unknowingly inserted in software before the bad guys do. 

The contest draws inspiration from "bug bounty" programs in the private sector open to hobbyists and professional penetration testers. Microsoft, for instance, offers a reward of up to $100,000 for attacking its software. General Motors earlier this year launched a car-hacking program that seeks glitch reports but doesn't yet pay for them. 

The military's new "Hack the Pentagon" program, unveiled Wednesday, potentially could offer cash prizes, according to a Defense Department announcement. Perhaps some of those bucks could come from the nearly $7 billion Pentagon Secretary Ash Carter expects to spend on cybersecurity in 2017. 

Only citizens willing to undergo a background check will be allowed to scour Pentagon computer programs for security vulnerabilities, according to Defense. Participants will not be angling for bugs in the F-35, but rather scrutinizing weaknesses in Defense webpages. The venture marks the first U.S. government foray into bug hacking, the department says. 

The "controlled, limited duration" trial will provide screened-hackers access to a pre-selected system, according to the Pentagon. No national security applications or other critical, "mission-facing" systems will be tested. 

Read more: Pentagon Googles ‘Innovation,’ Taps Eric Schmidt
Related: We’re On the Same Side, Carter Tells Silicon Valley

It is unclear what the screening process will entail or whether participation will be contingent on drug testing. Defense officials said details on eligibility rules will be out in coming weeks.

Background Checks Required

Background check requirements have stopped some cyber professionals from applying for government jobs, including FBI positions, Justice Department Inspector General Michael Horowitz wrote in a Nov. 10, 2015 memo to the attorney general on the bureau’s management challenges. FBI employees are barred from having used marijuana in the last three years or any other illegal drug in the past 10 years.

After Colorado and Washington State legalized recreational marijuana, James Clapper, director of national intelligence, sent a memorandum in October 2014 reminding agencies they “continue to be prohibited from granting or renewing a security clearance to an unlawful user of a controlled substance, which includes marijuana.”

HackerOne, a San Francisco-based firm that coordinates bug bounties for 500 organizations, said drug-use restrictions shouldn't have a significant effect on the outcome of the Pentagon's endeavor.

Many of its clients have other types of eligibility regulations, such as bans on contestants from Syria and Iran, or limiting competition to a certain skill set like mobile security. 

"As an experiment, it makes an incredible amount of sense to start with a constrained environment that you have a lot more confidence in," said Alex Rice, a HackerOne co-founder who launched a bounty program at Facebook.  

But "no question," the military will be excluding some top-notch players from helping secure Defense systems because of the marijuana prohibitions. 

The cultural disconnect between some creatives in the private sector and the military extends far beyond drug use, according to the Pentagon chief himself. 

“I am always challenging our people to think outside the five-sided box that is the Pentagon,” Carter said in a statement.  “Inviting responsible hackers to test our cybersecurity certainly meets that test. I am confident this innovative initiative will strengthen our digital defenses and ultimately enhance our national security.” 

Channeling Silicon Valley

"Hack the Pentagon" is one product of the Defense Digital Service, an office stood up last November that assigns 2-year IT gigs to Silicon Valley coders and other individuals outside the defense industrial base. 

The Defense Digital Service will kick off the bug bounty program this April. The office is one arm of a governmentwide tech squad comprising teams of programmers and statisticians, called the U.S. Digital Service. 

While the military’s contest might be the first federal bug bounty program announced, other agencies have been mulling public bug-finding initiatives, including the departments of Homeland Security and Commerce

DHS officials are contemplating using a "micropurchasing authority" to compensate ethical hackers, according to FCW. The General Services Administration successfully cut through the red tape of federal hiring and contracting by using the funding instrument, which has a cap of $3,500, to compensate coders. 

"We used it for code," said Darryl Peek, a cybersecurity strategist in DHS' Federal Network Resilience Division, of the micropurchasing authority. "Why can't we use it for bounty?"

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.