Tor Browser is the primary tool for quickly and securely accessing the Tor network. That status makes it a very tempting target, but if the plan is to find cracks in its armor, the most effective way to attract hackers is with juicy rewards. After offering up to half a million dollars for bugs in messengers like WhatsApp and Telegram, Zerodium confirmed it will hand out one million dollars to researchers who deliver new 0-day vulnerabilities in the Tor Browser.
The Tor network is probably our best option when it comes to browsing with security, privacy, and anonymity. Many groups are interested in finding holes (whether to exploit them or close them for good), and for logical reasons they focus their firepower on the popular Tor Browser. Its security has improved, and mitigation mechanisms in recent operating systems make direct attacks more difficult; however, we all know it is not a perfect solution, and there are bugs in its code waiting to be discovered.
That's where the security company Zerodium comes in, ready to distribute up to one million dollars in rewards for 0-day vulnerabilities affecting the Tor Browser on Windows 10 and Tails Linux 3.x. The final amounts depend on security parameters, but the biggest reward reaches $250,000 (the attack must work with JavaScript disabled), while the smallest offers a not-too-shabby $75,000. As expected, Zerodium has set a series of rules for its campaign. The "jobs" must be new, exclusive, and unknown, with a web page serving as the initial attack vector, and the ultimate goal of each exploit is remote code execution.
Anyone interested in claiming the rewards has until November 30 to share their efforts with Zerodium. Now, will it be enough? A million dollars is a lot of money, but something tells me that if a researcher holds a 0-day vulnerability in Tor Browser, they might get more cash for it...