Excludes: reconfiguration protocol, snapshot, recovery protocol. Todo items, things they know about but can't/won't fix. Excludes any kind of security issue.
Easy money it is not but this bounty program doesn't mean what you think it does.
Excludes: reconfiguration protocol, snapshot, recovery protocol. Todo items, things they know about but can't/won't fix. Excludes any kind of security issue.
Easy money it is not but this bounty program doesn't mean what you think it does.
The Normal protocol. The View Change protocol. The CTRL protocol from PAR (that you don't get to see often). Thousands of lines of code that are incredibly hard to get right.
All the fault models. The storage fault model alone is also not something you find many distributed systems attempting, let alone paying bounties for.
It's also not common to find bounties that go out of their way to help you. TigerBeetle's bounty ships with a state of the art Deterministic Simulation fuzzing tool that you can use to explore interesting state spaces quicker. It will even classify bugs as liveness or correctness for you. It's like your own Jepsen, except you can inject storage faults, speed up time, and replay anything you find from a seed.
Again, the only reason we were explicit about scope really, is because of our own experience doing bounty programs that were underspecified. For example, while it should be clear enough that this is a distributed systems and consensus bug bounty challenge, literally called “Viewstamped Replication Made Famous”, we didn't want anyone to be confused and think it was a security bug bounty. That's the only reason it's excluded, because we want people to break our consensus. Nevertheless, we do have small awards for interesting findings.
So I hope you'll give it a shot! We'd love to announce and award your findings. For example, why not take on the challenge during HYTRADBOI's database jam?
However, it was this experience of mine as a part-time security researcher that actually led to us creating the bug bounty program for TigerBeetle's consensus.
For example, if you're looking at another database and find a correctness bug, there might not be a bounty program at all. Whereas with TigerBeetle, there hasn't been a single valid report that we haven't awarded, at least so far.
It's also why we were careful to rather be upfront and explicit about scope, than disappoint anyone after the fact.
And we recognize that consensus is hard and takes time to learn, hence the $8192 award for correctness finds.
That said, I hope you can see from the leaderboard that we've been generous. For example, Alex Miller found a bug in Apple's O_DSYNC and we nevertheless awarded $1024 because it was such a great find (Apple thought so too!).
However many people are willing to put in the work, so why are you so critical of their program.
Do you think they are taking advantage of people who should charge more? Or do you think they will not get anyone good for such a low rate, and thus fool themselves into thinking they are secure?