Digi- ja väestötietovirasto

The Digital and Population Data Services Agency's bug bounty program expands to Suomi.fi Messages

Share
As of 13 February 2023, the Digital and Population Data Services Agency's bug bounty program will expand to cover Suomi.fi Messages. In the program, the Agency cooperates with white hat hackers to identify potential security deficiencies in the services. The bug bounty program will continue until 30 April 2023.

‘At worst, the vulnerabilities of digital services lead to a successful data breach.It is very useful to carry out long-term communal testing, such as the bug bounty program, on services that are open to the Internet,’ says Pekka Ristimäki, Head of Information Security at the Digital and Population Data Services Agency.

Hacking during the program does not compromise the security of the systems. On the contrary, a large group of testers enables more extensive testing and efficient identification of potential vulnerabilities.

How does hacker collaboration work?

Professional and amateur hackers are invited to participate in the bug bounty program to carry out information security research on the services targeted by the program. The programs are communal vulnerability security tests in which external testers, i.e. hackers, are given the opportunity to test organisations’ digital services within the agreed principles and limitations.

‘We have engaged in similar cooperation with hackers in the past, and the experiences have been good. The bug bounty program complements our standard application testing. At the same time, talented hackers are given the opportunity to test their skills with permission and make some money on the side,’ says Pekka Ristimäki.

Hackers register for testing and commit to following the established rules. If vulnerabilities are found, the person who finds them will be paid a fee in proportion to the significance of the finding. The fees range between €100 and €30,000.

The bug bounty program is produced by Hackrfi Oy, a company specialising in the management of communal vulnerability coordination and information security testing. The Digital and Population Data Services Agency's bug bounty program takes place from 31 October 2022 to 30 April 2023. Participants will be invited on the basis of an application.

Read more about the Digital and Population Data Services Agency's bug bounty program and apply to it on the website of Hackrfi Oy: https://www.hackr.fi/ohjelmat/DVV-BB.html

On 31 October 2022, the Digital and Population Data Services Agency launched the bug bounty program, which looks for possible information security vulnerabilities in Suomi.fi services. The program tests the Suomi.fi Web Service as well as the Suomi.fi e-Identification, Suomi.fi e-Authorizations and Suomi.fi Messages interface.

Suomi.fi is an online service that collects public services and guidelines for people at different stages of their lives. You can also use Suomi.fi to check your own data in the registers of different authorities, receive official mail electronically and grant and request rights to act on behalf of another person or company. Suomi.fi is developed by the Digital and Population Data Services Agency.

Keywords

Contacts

Digital and Population Data Services Agency, Head of Information Security Pekka Ristimäki, tel. +358 295 535 048, firstname.lastname[at]dvv.fi


 

Images

About Digi- ja väestötietovirasto

Digi- ja väestötietovirasto
Digi- ja väestötietovirasto
Lintulahdenkuja 2
00530 HELSINKI

0295 536 000 (vaihde)https://dvv.fi

Digital and Population Data Services Agency (The Finnish Digital Agency)

Digital and Population Data Services Agency (The Finnish Digital Agency) promotes the digitalisation of society, secures the availability of information and provides services related to customers’ life events.

The Digital and Population Data Services Agency (The Finnish Digital Agency) sees to the maintenance of the Population Information System, which is the foundation for our society, and to the digitalisation of society. The agency’s tasks include civil marriages, name and address changes, guardianship and administrative guardianship, maintenance of the Population Information System, development of solutions for electronic identification, as well as the development and maintenance of centralised support services for e-services. E-service support services include the Suomi.fi Web Service, electronic messages from authorities (Suomi.fi Messages) as well as authorisation for acting on behalf of another party (Suomi.fi e-Authorization).

http://dvv.fi/en

Subscribe to releases from Digi- ja väestötietovirasto

Subscribe to all the latest releases from Digi- ja väestötietovirasto by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Digi- ja väestötietovirasto

Datautbytet om flyttningar mellan Finland och Estland har inletts – 13 266 personer har adress i båda länderna17.12.2025 08:00:00 EET | Pressmeddelande

Det automatiska datautbytet om personer som flyttar mellan Finland och Estland inleddes den 2 december 2025. När någon flyttar från det ena landet till det andra meddelar inflyttningsstaten detta till utflyttningsstaten, som då i sitt eget befolkningsregister antecknar personen som utflyttad. Då upphör personens adress och hemkommun i utflyttningsstaten.

Nu når myndigheternas digitala post bättre fram – du får en notifikation när du identifierar dig i myndigheternas elektroniska tjänster2.12.2025 07:03:00 EET | Pressmeddelande

Från och med 2.12.2025 får du en notifikation i samband med Suomi.fi-identifikation om du har ett nytt oläst meddelande i Suomi.fi-meddelanden. Notifikationen visas när du identifierar dig i statens, kommunens eller välfärdsområdets elektroniska tjänster. Ändringen bidrar till att säkerställa att mottagaren säkert ser viktiga myndighetsmeddelanden, såsom beslut, fakturor och tidsbokningsbrev.

Viranomaisten lähettämä digiposti tavoittaa nyt varmemmin - saat ilmoituksen kun tunnistaudut viranomaisten sähköisiin palveluihin2.12.2025 07:03:00 EET | Tiedote

2.12.2025 alkaen saat Suomi.fi-tunnistuksen yhteydessä muistutuksen, jos sinulla on uusi lukematon viesti Suomi.fi-viesteissä. Muistutus näkyy, kun tunnistaudut valtion, kunnan tai hyvinvointialueen sähköisiin asiointipalveluihin. Muutos auttaa varmistamaan, että tärkeät viranomaisviestit, kuten päätökset, laskut ja ajanvarauskirjeet, tulevat varmasti huomatuiksi.

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye