Pwning Santa before the bad guys do: A hybrid bug bounty / CTF for container isolation
Freedom of the Press Foundation is developing Dangerzone, an open-source tool that uses multiple layers of containerization (gVisor, Linux containers) to sanitize untrusted documents. The target users of this tool are people who may be vulnerable to malware attacks, such as journalists and activists. To ensure that Dangerzone is adequately secure, it received a favorable security audit in December 2023, but never had a bug bounty program until now. We are kick-starting a limited bug bounty program for this holiday season, that challenges the popular adage “containers don’t contain”. The premise is simple; sent Santa a naughty letter, and its team of elves will run it by Dangerzone. If your letter breaks a containerization layer by capturing a flag, you get the associated bounty. Have fun! submitted by /u/FreedomofPress [link] [comments]Technical Information Security Content & DiscussionRead More