The StopCovid application in the hands of bug hunters
Date:
Changed on 03/06/2020
France is the first country to use a Bug Bounty program to secure its contact tracing application. In case of detection of flaws, these will be reported to the StopCovid project team in charge of the development of the application via detailed reports, in order to make potential corrections.
The Bug Bounty offers enhanced bug and vulnerability scanning capabilities, thanks to the participation of ethical hackers who put themselves in the shoes of malicious hackers. As part of the StopCovid project, around 20 experts from all over Europe will start testing the security of the application on Wednesday 27 May. They will be followed from June 2nd by all hackers from the YesWeHack community who wish to do so. In the event that the community discovers a vulnerability, the StopCovid project team will be able to correct the bugs that are critical to the proper functioning of the application.
Feedback from these contributors will be published on the YesWeHack website and uploaded to the GitLab Inria StopCovid on which the StopCovid application source code is published. Beyond this community, the source code will be accessible to anyone who wishes to consult it and make contributions.
ANSSI and Inria are pleased to be able to call on the community of cybersecurity experts through the use of the Bug Bounty. Sovereignty, confidentiality and security are the main principles governing this approach. This general mobilization will guarantee optimal reliability of the application throughout its life cycle.
"For the ANSSI, the security of the application must be ensured by the combination of several processes. The assistance in the secure design and then the audit of the application carried out by our experts must be completed by the control of the code published in open-source by the digital community and by the organization of research for computer flaws, such as bug bounty," explains Guillaume Poupard, ANSSI's general director.
"For Inria, as for all the partners and contributors of the StopCovid project team, cybersecurity is a major concern, in order to provide citizens with an application based on the highest standards in terms of security and the latest cryptographic algorithms. As in any computer system, flaws can exist, hence the importance of the involvement in the project of ANSSI and specialists in the field, such as YesWeHack, to protect us from possible malicious attacks", says Bruno Sportisse, CEO of Inria.