Facebook launches bug bounty program for Libra

Offering up to $10,000 for uncovering critical blockchain security issues.
By Rob Marvin  for PCMag  on 
Facebook launches bug bounty program for Libra
Screens of a smart phone and a laptop display the logos of Libra and Facebook. Credit: aytac unal / anadolu agency / Getty Images

PCMag.com is a leading authority on technology, delivering Labs-based, independent reviews of the latest products and services. Our expert industry analysis and practical solutions help you make better buying decisions and get more from technology.

As Facebook's ambitious plans for Libra face intense regulatory scrutiny both in the US and around the globe, the nonprofit Libra Association that governs the Libra blockchain is pushing forward on the technology side.

After more than two months in beta testing with 50 security researchers and blockchain experts, the Libra Bug Bounty Program is now open to the public, the Libra Association announced today. The association is inviting security researchers around the world to uncover bugs and vulnerabilities in the open-source Libra Core code, which remains in an early stage version called testnet.

The conceit of Libra relies upon compromising the traditional decentralization benefits of blockchain technology in order to accelerate transaction speeds, with the goal of transacting Libra nearly instantaneously between digital wallets and within Facebook-owned Messenger and WhatsApp. This trade-off—a permissioned blockchain where only Libra Association members operate a limited number of nodes—heightens already paramount security concerns about a platform and products designed to serve as financial infrastructure for millions, pegged to a basket of real-world currencies.

Launched in partnership with big bounty platform HackerOne, the Libra Bug Bounty program will pay out up to $10,000 for uncovering critical flaws in the Libra blockchain code. Rewards payments scale up based on type and severity, and the Libra Association said it will offer bonus multipliers to "spotlight" bugs that "highlight certain areas of the blockchain to attract research attention."

"Our rewards program is designed to encourage members of the security community to dig deep, helping us find even the most subtle bugs. We want to help our researchers uncover issues while the Libra Blockchain is still in testnet and no real money is in circulation," said Michael Engle, the Libra Association's Head of Developer Ecosystem.

Facebook's bug bounty program dates back to 2011, and it's expanded over the years to include new criteria such as developer data abuse in the wake of the Cambridge Analytica scandal. Aanchal Gupta, Security Director at Facebook-owned subsidiary Calibra (which is developing a Libra wallet app to be embedded directly in Facebook apps and services), said he hopes developers will bring a "diversity of perspectives and expertise to this initiative while holding the Libra Blockchain to the highest security standard."

Calibra head David Marcus told Congress ad nauseum that Libra would not launch until all regulatory concerns are addressed and all approvals are received. So between regulatory pressure, reported second thoughts from Libra Association members, and the sheer scale of actually developing and launching the Libra Blockchain worldwide, we're still a long way off from anything resembling a finished product. In the meantime, at least Libra is working out some of the bugs.

More information is available in the open-source Libra documentation, and on HackerOne.


Recommended For You
This stoner comedy is a perfect pick for 420
The ensemble of "Hanky Panky" crowd together over a pantsuit.

'Abigail' review: Savage crowdpleaser boasts a ballerina vampire
Alisha Weir plays a vampire ballerina in "Abigail."

'Stress Positions' review: John Early's COVID comedy goes boldly cringe
John Early in "Stress Positions."

'Rebel Moon: Part Two - The Scargiver' review: Can Zack Snyder save his space epic? 
Djimon Hounsou, goes to war as Titus in "Rebel Moon — Part Two: The Scargiver."

The 'Civil War' AI controversy, explained
A woman in a bulletproof vest that reads "press."

More in Tech
How to watch Game 1 of New York Knicks vs. Philadelphia 76ers online for free
Joel Embiid of the Philadelphia 76ers reacts during the fourth quarter

The 28 best true crime documentaries on Max
Images from true crime documentaries on Max

How to watch Hellas Verona vs. Udinese online for free
Federico Bonazzoli of Hellas Verona FC celebrates after scoring

How to watch Manchester City vs. Chelsea online for free
Kyle Walker of Manchester City

How to watch Delhi Capitals vs. Sunrisers Hyderabad online for free
By Lois Mackenzie
Members of  Sunrisers Hyderabad team

Trending on Mashable
The Cybertruck's failure is now complete
Elon Musk standing in front of a Cybertruck with two bullet marks in its windows.

NYT Connections today: See hints and answers for April 20
A phone displaying the New York Times game 'Connections.'

Wordle today: Here's the answer and hints for April 20
a phone displaying Wordle


NYT Connections today: See hints and answers for April 19
A phone displaying the New York Times game 'Connections.'
The biggest stories of the day delivered to your inbox.
This newsletter may contain advertising, deals, or affiliate links. Subscribing to a newsletter indicates your consent to our Terms of Use and Privacy Policy. You may unsubscribe from the newsletters at any time.
Thanks for signing up. See you at your inbox!