Digi- ja väestötietovirasto

Hackers look for gaps in the information security of Suomi.fi services – cooperation enables more secure digital services

Share

The Digital and Population Data Services Agency is starting a new cooperative program with white hat hackers. The aim of the bug bounty program, which starts today on 16 October 2023, is to discover information security vulnerabilities in services such as Suomi.fi.

In the photo there is a woman sitting and looking at Suomi.fi web service
The aim of the bug bounty program, which starts today on 16 October 2023, is to discover information security vulnerabilities in services such as Suomi.fi. The Digital and Population Data Services Agency

Pekka Ristimäki, Head of Information Security at the Digital and Population Data Services Agency, points out that cybercrime is growing constantly, with criminal attacks targeting various digital services more and more often.

- Digital services play an important role in all of our lives, as they allow us to use everyday services easily whenever and wherever. Testing systems in cooperation with white hat hackers is an excellent way to develop digital services and test their security, says Ristimäki.

Hacker cooperation complements normal application testing

A white hat hacker is a person who has permission to look for vulnerabilities in an information system. Bug bounty programs promote ethical and lawful conduct among people interested in hacking.

Hackers invited to participate in bug bounty programs can be either professionals or hobbyists. They test the information security of the services included in the bug bounty program. In a bug bounty program, external testers, i.e. hackers, are given the opportunity to test organisations’ digital services within the agreed principles and limitations.

– With societal functions becoming increasingly digitalised at a fast pace, the reliability of information systems is more important than ever. This is now the third time we are cooperating with white hat hackers. We’ve had very good experiences with previous cooperation. The cooperation nicely complements our normal application testing and enables more efficient testing of digital services and the development of their security. At the same time, the bug bounty program gives talented hackers the opportunity to test their skills with permission and make some money on the side, says Pekka Ristimäki.

Hackers register for testing and commit to following the established rules. If vulnerabilities are found, the person who finds them will be paid a fee in proportion to the significance of the finding. The fees range between €100 and € 30,000.

The bug bounty program is produced by Hackrfi Oy, a company specialising in the management of communal vulnerability coordination and information security testing. The Digital and Population Data Services Agency’s bug bounty program will continue for a year, starting on 16 October 2023. People are invited to participate based on applications.

Read more about the Digital and Population Data Services Agency’s bug bounty program and apply to it on the Hackrfi Oy website: https://www.hackr.fi/ohjelmat/DVV-BB.html

What is white hat hacking?

  • A white hat hacker is a person who gets permission to test for vulnerabilities in information systems.
  • White hat hackers are used in information security testing through various bug bounty programs.
  • A white hat hacker tests information systems ethically and lawfully.
  • Hackers register for testing and commit to following the established rules.
  • If vulnerabilities are found, the person who finds them will be paid a fee in proportion to the significance of the finding.

Keywords

Contacts

Images

In the photo there is a woman sitting and looking at Suomi.fi web service
The aim of the bug bounty program, which starts today on 16 October 2023, is to discover information security vulnerabilities in services such as Suomi.fi.
Download

Digital and Population Data Services Agency (The Finnish Digital Agency)

Digital and Population Data Services Agency (The Finnish Digital Agency) promotes the digitalisation of society, secures the availability of information and provides services related to customers’ life events.

The Digital and Population Data Services Agency (The Finnish Digital Agency) sees to the maintenance of the Population Information System, which is the foundation for our society, and to the digitalisation of society. The agency’s tasks include civil marriages, name and address changes, guardianship and administrative guardianship, maintenance of the Population Information System, development of solutions for electronic identification, as well as the development and maintenance of centralised support services for e-services. E-service support services include the Suomi.fi Web Service, electronic messages from authorities (Suomi.fi Messages) as well as authorisation for acting on behalf of another party (Suomi.fi e-Authorization).

https://dvv.fi/en

Alternative languages

Subscribe to releases from Digi- ja väestötietovirasto

Subscribe to all the latest releases from Digi- ja väestötietovirasto by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Digi- ja väestötietovirasto

Det lönar sig att upprätta en intressebevakningsfullmakt även om du inte kunde bry dig mindre6.5.2024 09:43:22 EEST | Tiedote

Myndigheten för digitalisering och befolkningsdatas kampanj I egna händer påminner igen om att upprätta en intressebevakningsfullmakt. Ämbetsverket utvecklar kontinuerligt nya tjänster för att göra det smidigare att uträtta ärenden åt någon annan, eftersom de behövs när vår befolkning åldras. Det går nu lättare och snabbare att ta i bruk en intressebevakningsfullmakt på nätet. Dessutom blir det snart lättare för intressebevakningsfullmäktige att sköta ärenden som gäller fullmaktsgivarens egendom. Har du redan gjort en intressebevakningsfullmakt?

EVVK? Edunvalvontavaltakirja kannattaa tehdä, vaikka ei voisi vähempää kiinnostaa6.5.2024 09:43:22 EEST | Tiedote

Digi- ja väestötietoviraston Omissa käsissä -kampanja muistuttaa jälleen tekemään edunvalvontavaltuutuksen. Virasto kehittää jatkuvasti uusia palveluja toisen puolesta asioinnin sujuvoittamiseksi, sillä niitä tarvitaan väestömme ikääntyessä. Edunvalvontavaltuutuksen käyttöön ottaminen sujuukin nyt helpommin ja nopeammin verkossa. Lisäksi edunvalvontavaltuutetut pääsevät pian hoitamaan valtuuttajan omaisuuteen liittyviä asioita helpommin. Joko sinä olet tehnyt edunvalvontavaltuutuksen?

Suomi.fi-mobiilisovellus uudistuu 22.4.2024 – Katso miten muutos vaikuttaa sinuun!17.4.2024 15:05:00 EEST | Tiedote

Suomi.fi-mobiilisovelluksen uudet Android- ja iOS-versiot julkaistaan 22.4.2024. Uudistuksen myötä sovelluksen ulkonäkö ja toiminnallisuudet uudistuvat. Uudessa Suomi.fi-mobiilisovelluksessa on parannettu muun muassa sovelluksen käytettävyyttä, saavutettavuutta ja navigaatiorakennetta. Kun uusi sovellus on julkaistu, vanhojen sovellusversioiden käyttäminen ei ole enää mahdollista.

The new versions of Suomi.fi mobile application will be launched 22.4.2024: See how the change affects you!17.4.2024 15:05:00 EEST | Press release

The new Android and iOS versions of the Suomi.fi mobile application will be launched 22.4.2024. As a result of the update, the appearance and functionalities of the application will change. The new application has improved usability, accessibility and navigation structure. Once the new application is published, it will no longer be possible to use older versions of the application.

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
HiddenA line styled icon from Orion Icon Library.Eye