ExpressVPN just majorly upped its bug bounty reward


ExpressVPN has revealed it is now offering ten times more money to anyone able to uncover security bugs.
The company announced, via Bugcrowd’s Bug Bounty program, that it will reward anyone who is able to find and demonstrate a “critical security bug” on ExpressVPN’s in-house technology, TrustedServer, with $100,000.
The company’s previous top reward was $10,000.
Monitoring user traffic
A “critical security bug” would be either something that would allow unauthorized access to a VPN server endpoint, or allow remote code execution (such as malware).
It would also mean any vulnerabilities in the VPN server that result in the leaking of the clients’ real IP addresses, or which would allow third parties to monitor user traffic.
TrustedServer’s goal, as ExpressVPN explains, is to “significantly minimize” problems inherent to traditional server management.
At its core, it’s an operating system, with “multiple layers of protection”, such as a custom Linux distribution built on Debian Linux and developed in-house, a reproducible build and verification system ensuring the authenticity of the source code and the build system, or the ability for ExpressVPN to know exactly what’s running on each and every server.
“Traditionally, VPN infrastructure may be vulnerable to several privacy and security risks,” commented Shaun Smith, Software Engineering Fellow at ExpressVPN and the architect behind TrustedServer.
“This is because most traditional approaches to managing server infrastructure cannot account for various security and privacy risks that are important for VPN service providers to mitigate. We built TrustedServer to address those risks, and make the same solution scalable, consistent, and secure across all our servers.”
Virtual Private Networks were once a staple of network security. However, in recent times, especially with the emergence of remote and hybrid working, and with cybercrime growing as dangerous as never before, organizations have been increasingly turning towards zero-trust network access (ZTNA).
Audio player loading… ExpressVPN has revealed it is now offering ten times more money to anyone able to uncover security bugs. The company announced, via Bugcrowd’s Bug Bounty program, that it will reward anyone who is able to find and demonstrate a “critical security bug” on ExpressVPN’s in-house technology, TrustedServer,…
Recent Posts
- Silo season 3: Everything we know so far about the Apple TV Plus show
- The iOS 18.4 beta brings Matter robot vacuum support
- Philips Monitors is now offering a whopping 5-year warranty on some of its displays, including a gorgeous KVM-enabled business monitor
- The secretive X-37B space plane snapped this picture of Earth from orbit
- Beyond 100TB, here’s how Western Digital is betting on heat dot magnetic recording to reach the storage skies
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010