OVH offers up to €20,000 to bug bounty hunters

Cloud and hosting company OVH has given more details about its bug bounty programme which it announced in July. It is offering to pay developers for any bugs that they report to OVH. Rewards start at €50 and run as high as €20,000 pay out. For example Microsoft pay out up to $100,000, Apple $200,000. While this isn’t the largest bounty program, OVH are focused on bugs in their own infrastructure rather than zero-day bugs in products from other vendors.

OVH offering up to €20,000 per bug

Octave Klaba, co-founder and CTO, OVH announced in his keynote that the programme had gone from beta to being publicly accessible. Despite applause from the audience he didn’t go into a lot more detail. This was a surprise as it seemed only a few of those present were aware of the programmes existence.

Octave Klaba, Chairman, CTO and Founder OVH (source LinkedIn)
Octave Klaba, Chairman, CTO and Founder OVH

At the press conference immediately after the keynote, Klaba put more perspective into the programme. This was his idea to start with but OVH faced delays getting it up and running. According to Klaba: “We wanted to do this 2-3 years ago but there were legal issues in France.”

Klaba didn’t elaborate on what those legal issues were. It might be that they were about paying people for what could be seen as hacking into code. France has some strict controls on intellectual property and OVH would have wanted to ensure that anyone reporting bugs could do so safely. Interestingly Klaba went on to say: “We don’t pay the people, we have advice from the partner.”. The implication is that not all payments are from OVH. This suggests that this is more than just issues with OVH code and infrastructure.

We asked Klaba if there were plans to increase the payout. After all €20,000 is well below the Dark Net rate for bugs. Klaba responded: “We will see the revenue higher.” However, he declined to say when and by how much. He did say that there had already been: “a lot of feedback from bounty hunters and more than 50 cases have been fixed and paid.”

Conclusion

Bug bounty programmes are becoming increasingly common across software vendors. As cloud vendors build out their own services, extending bug bounty programmes to their infrastructure makes sense. This will not only improve the underlying code but also harden the infrastructure.

The only issue here is one of risk/reward. The risks are increasing faster than the rewards which means vendors and cloud providers will need to offer ever larger sums to bounty hunters. If not, there are plenty of companies operating inside the Dark Net that will happily bid for the information.

Disclaimer: OVH paid for my fuel and Eurotunnel ticket so I could attend the event

Previous articleSeventh heaven for Saratoga
Next articleUltimate gains ultimate TRUSTe privacy certification
Ian Murphy
Ian Murphy is an enterprise technology journalist, podcaster, editor and industry analyst with more than 40 years' experience covering enterprise IT, cybersecurity, networking, cloud and artificial intelligence. His career combines hands-on technology experience with long-term industry analysis and journalism. In the 1980s, Ian authored an industry report on expert systems, an early application of artificial intelligence, and founded an IT training company delivering accredited training on enterprise software. He later became a Microsoft Certified Trainer, helping professionals understand and apply business technologies. Alongside his work as a freelance journalist and analyst, Ian developed software, deployed enterprise networks and managed software and technical support teams. That practical experience informs his writing, providing insight into not only what technologies promise, but how they are implemented and used in real enterprise environments. Ian has written thousands of articles, produced industry research, hosted podcasts and interviewed technology leaders across enterprise software, infrastructure, cybersecurity and AI. His work focuses on helping CIOs, IT leaders and technology professionals understand the opportunities, challenges and real-world impact of emerging technologies.

LEAVE A REPLY

Please enter your comment!
Please enter your name here