Hacker News new | past | comments | ask | show | jobs | submit login

They don't want to 'buy' the exploit outright, just fund the R&D. Thank you sensationalist media.



I don't understand, it seems like researchers have to pay to enter and then are only given the funding if successful, that's not exactly funding R&D, more of a contest. It seems really strange that Russia would be offering this kind of bounty in effort to improve the program's security, don't they know how many activists and dissidents use it. Is the sole reason to aid their own spies?

They should just provide funds on a site such as https://hackerone.com/

I really wish the US government would offer bounties for their sites and systems. Right now if people try to exploit a US government system, even if they have the intention to properly disclose the vulnerability they face prosecution.


It is definitely R&D to find a vulnerability in TOR or lack thereof, it's just that BBC as usual is arbitrarily choosing what to report and what to stay silent about.

Look no further than the tender page: http://zakupki.gov.ru/epz/order/notice/zkk44/view/common-inf...

Here they explicitly state that it's a tender for 'Выполнение научно-исследовательской работы, шифр «ТОР (Флот)»' (Research and Development works, code "TOR (Navy)")

Then it's a closed tender (stated in the same document), meaning that they come up with a list of organisations they invite to participate in this tender. No organization they did not invite can participate.

So you see this is nothing like a bounty.

>it seems like researchers have to pay to enter

I wager they are required by law to demand some sum of money, maybe this sum is determined as a function of a tender value; I don't believe there is some additional meaning to asking people to pay 5500 usd to participate in a closed tender.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: