{"id":9764,"date":"2017-10-30T13:45:21","date_gmt":"2017-10-30T09:45:21","guid":{"rendered":"https:\/\/me-en.kaspersky.com\/blog\/?p=9764"},"modified":"2019-11-15T15:23:42","modified_gmt":"2019-11-15T11:23:42","slug":"even-more-transparency","status":"publish","type":"post","link":"https:\/\/me-en.kaspersky.com\/blog\/even-more-transparency\/9764\/","title":{"rendered":"Astrologers proclaim 2018 the year of transparency. Our bug bounty just increased \u2014 twentyfold"},"content":{"rendered":"<p>Hey folks,<\/p>\n<p>I have great news.<\/p>\n<p>No, let\u2019s start again.<\/p>\n<p>I HAVE GREAT NEWS!<\/p>\n<p>We\u2019re about to launch (deep breath) the Global Transparency Initiative. The clue\u2019s in the name: It\u2019s all about, well yes, transparency. Now for some details.<\/p>\n<p>BTW, there\u2019s a tasty offer for all cybersecurity experts coming up below. So make sure you read to the end!<\/p>\n<p><em>What is this Global Transparency Initiative, exactly?<\/em><\/p>\n<p>In the very near future \u2014 the beginning of next year, to be precise, we\u2019ll open up the source code of our products for third-party analysis and audit. We\u2019ve long carried out regular internal audits of this kind, but since that\u2019s no longer enough, we are totally OK with taking one more step \u2014 we have nothing to hide anyway.<\/p>\n<p>Early 2018 will see the unveiling of the first of three planned Transparency Centers. These three centers will be up and running in Europe, Asia, and the US by 2020.<\/p>\n<p>Let\u2019s cut to the chase: We\u2019ll open not only the source code of our products, but also updates of our AV databases and updates to the software itself. So if there are vulnerabilities or, God forbid, backdoors that we don\u2019t know about ANYWHERE, they will be revealed and we won\u2019t be able to keep it under wraps.<\/p>\n<p>But we wouldn\u2019t want to anyway!<\/p>\n<p><em>Why are we doing this? <\/em><\/p>\n<p>Very simple. Cybersecurity is based on trust, and trust without transparency ain\u2019t possible. No, sir. Not unlike life\u2019s other vitals.<\/p>\n<p>You wouldn\u2019t have surgery if you didn\u2019t trust the guy holding the knife. You wouldn\u2019t entrust your child to a kindergarten if you yourself weren\u2019t allowed inside. You wouldn\u2019t buy groceries if the label didn\u2019t have a best-by date. Let me stress that what we\u2019re talking about here isn\u2019t even actual flaws, but simply the possibility of them. When it comes to what matters most, there should be no trade-offs.<\/p>\n<p>No one believes that more than we do.<\/p>\n<p>Our users are our be-all and \u201cendpoint\u201d-all, so we\u2019re ready to strip naked, digitally speaking. We\u2019re going to x-ray our products and destroy the magic halo that surrounds the IT world. The magic\u2019s fairly minimal, to be honest \u2014 just clean code and no skulduggery.<\/p>\n<p>One more thing. You probably noticed we\u2019re living in times of turbulence and near-revolutionary change \u2014 the era of post-truth, when emotions are more important than facts. And in such a world, when we find an island of reliability and security, we need to drop anchor and wade ashore.<\/p>\n<p>Kaspersky Lab is one such island, and we are willing to prove it.<\/p>\n<p>I firmly believe that this is the natural result of two decades of cutting-edge development. If we didn\u2019t launch this initiative <em>now<\/em>, we\u2019d do it in a few years anyway. If <em>we<\/em> didn\u2019t launch it, someone else would. So I want to extend yet another big thank-you to America\u2019s politicians. Thanks to them, we\u2019re again ahead of the global curve: I\u2019m confident that in a couple of years this kind of transparency will become a new industry standard. It\u2019s always good to be a pioneer.<\/p>\n<p>Important note: You should not be worried that we\u2019ll disclose our source code to just anyone. Our main goal is to protect our customers, and therefore we will ensure that the source code is disclosed only to regulators and authorized law enforcement. It will be checked under our close supervision in a Sensitive Compartmented Information Facility (<a target=\"_blank\" href=\"https:\/\/en.wikipedia.org\/wiki\/Sensitive_Compartmented_Information_Facility\" rel=\"noopener noreferrer nofollow\">SCIF<\/a>). IT WILL NOT BE physically provided to any outside agency \u2014 the review will take place in the independent center where we invite regulators.<\/p>\n<p>Once again \u2014 we will not provide source code on a memory stick to anyone who asks. It will be a strongly regulated but nevertheless transparent procedure accomplished in a third-party-provided SCIF.<\/p>\n<p>And now for the offer I promised.<\/p>\n<p>Within the Global Transparency Initiative framework, we\u2019ve upgraded our bug bounty program. All of the juicy details will be rolled out by the end of this year, but for now here\u2019s a little spoiler: The top reward will hit $100,000. That\u2019s, one sec, 20 times as high as the previous best offer.<\/p>\n<p>So, cybersecurity experts of the world, <a href=\"mailto:transparency@kaspersky.com\" target=\"_blank\" rel=\"noopener\">unite<\/a>! Together we will banish mistrust and continue to protect people all around the world.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We\u2019re launching the Global Transparency Initiative. What is it? Eugene Kaspersky explains.<\/p>\n","protected":false},"author":13,"featured_media":9765,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,1485],"tags":[1513,1535,352,499,1536,97,1515],"class_list":{"0":"post-9764","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"category-special-projects","9":"tag-bug-bounty","10":"tag-code-analysis","11":"tag-kaspersky-lab","12":"tag-products-2","13":"tag-reward","14":"tag-security-2","15":"tag-transparency"},"hreflang":[{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/even-more-transparency\/9764\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/even-more-transparency\/13126\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/even-more-transparency\/12032\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/even-more-transparency\/11648\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/even-more-transparency\/14694\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/even-more-transparency\/14416\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/even-more-transparency\/19105\/"},{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/even-more-transparency\/4353\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/even-more-transparency\/19943\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/even-more-transparency\/9725\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/even-more-transparency\/8453\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/even-more-transparency\/15131\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/even-more-transparency\/18573\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/even-more-transparency\/19000\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/even-more-transparency\/18992\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/me-en.kaspersky.com\/blog\/tag\/kaspersky-lab\/","name":"Kaspersky Lab"},"_links":{"self":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/9764","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=9764"}],"version-history":[{"count":2,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/9764\/revisions"}],"predecessor-version":[{"id":14798,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/9764\/revisions\/14798"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/9765"}],"wp:attachment":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=9764"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=9764"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=9764"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}